Add Google as an IdP and enable Custom Authentication

Add Google as an IdP and enable Custom Authentication

Custom authentication with Google enables SAML-based single sign-on (SSO) from Google to Zoho Directory. Once configured, users in your organization can access Zoho Directory from Google without signing in to Zoho Directory.

This article outlines the steps to configure custom authentication in Zoho Directory using Google as the Identity Provider (IdP).

Prerequisites

In Zoho Directory - Roles that can perform this action:
  1. Organization Owner
  2. Organization Admin
  3. Security Admin role
In Google - Roles that can perform this action:
  1. Organization Owner
  2. Super Admin

In Google: Configure SAML

  1. Sign in to your Google Admin console.
  2. On the left panel, click Apps, then click Web and mobile apps from the dropdown.
  3. Click Add App, then click Add custom SAML app.
  4. In the App details page, enter the App name as "Zoho Directory". You can optionally add a description and icon.
  5. Click CONTINUE.
  6. In the Google Identity Provider details page, copy the SSO URL and download the Certificate. You'll need to submit this URL and the downloaded certificate to add Google as an IdP in Zoho Directory.
  7. Click CONTINUE.
  8. In the Service provider Details page, enter the ACS URL and Entity ID.
  9. NotesYou can find the ACS URL and Entity ID in the Zoho Directory's Identity Provider page.
  10. Select the Signed response checkbox.
  11. Select EMAIL as the Name ID Format.
  12. Click Continue. The Attribute mapping window is optional, and can be configured if you need any custom attributes in the SAML Response. To add an attribute mapping:
    1. Click ADD MAPPING.
    2. Use the Select field drop-down to select a field name and enter the respective attribute under App Attribute.
  13. Click Finish.

In Zoho Directory: Add Google as an IdP

  1. Sign in to Zoho Directory, then click Admin Panel.
  2. Click Security on the left menu.
  3. Select Routing Policies, then go to the Identity Providers tab.
  4. Click Add Identity Provider.
  5. Choose SAML as the SSO Protocol, then enter a name of your IdP in the IdP name field.
  6. Paste the SSO URL in the Sign-in URL field.
  7. Upload the downloaded Certificate in the X509 certificate field.
  8. Click Add. Google will be added as an Identity Provider in Zoho Directory.

In Zoho Directory: Add Routing Policy to enable Custom Authentication

  1. On the same page, go to Routing Policies tab and click Add Policy.
  2. Enter a name for the policy, then select the members you want to apply the policy to.  
  3. Select if any groups whose users should be excluded from the policy, even if they are part of the selected groups.
  4. Click Next.
  5. Under Authentication Modes, enable the Identity providers toggle, then select the IdP you added from the list.
  6. Click Next.
  7. Set Session Settings if required, then click Add. A routing policy will be created and members of this policy will use this IdP to sign in.