Add JumpCloud as an IdP and enable Custom Authentication

Add JumpCloud as an IdP and enable Custom Authentication

Custom authentication with JumpCloud enables SAML-based single sign-on (SSO) from JumpCloud to Zoho Directory. Once configured, users in your organization can access Zoho Directory from JumpCloud without signing in to Zoho Directory.

This article outlines the steps to configure custom authentication in Zoho Directory using JumpCloud as the Identity Provider (IdP).

Prerequisites

In Zoho Directory - Roles that can perform this action:
  1. Organization Owner
  2. Organization Admin
  3. Security Admin role

In JumpCloud: Configure SAML

  1. Sign in to JumpCloud's administrator console.
  2. Go to Applications, then click on the plus icon.
  3. Search for "Zoho", then click configure for the result.
  4. Enter "Zoho Directory" under Display Label.
  5. Enter your ACS URL in the ACS URL field.
  6. NotesYou can find the ACS URL in Zoho Directory's Identity Provider page.
  7. Copy the IDP URL, then click activate.
  8. Click on the added app, then click IDP Certificate Valid, and click Download certificate. You'll need to submit the IDP URL and the downloaded certificate to add JumpCloud as an IdP in Zoho Directory.

In Zoho Directory: Add JumpCloud as an IdP

  1. Sign in to Zoho Directory, then click Admin Panel.
  2. Click Security on the left menu.
  3. Select Routing Policies, then go to the Identity Providers tab.
  4. Click Add Identity Provider.
  5. Choose SAML as the SSO Protocol, then enter the name of your IdP in the IdP name field.
  6. Paste the IDP URL under Sign-in URL and upload IDP Certificate under X509 certificate field.
  7. Click Add. JumpCloud will be added as an Identity Provider in Zoho Directory.

In Zoho Directory: Add Routing Policy to enable Custom Authentication

  1. On the same page, go to Routing Policies tab and click Add Policy.
  2. Enter a name for the policy, then select the members you want to apply the policy to.
  3. Select if any groups whose users should be excluded from the policy, even if they are part of the selected groups.
  4. Select the priority of this policy with other routing policies.
  5. Click Next.
  6. Under Authentication Modes, enable the Identity providers toggle, then select the IdP you added from the list.
  7. Click Next.
  8. Set Session Settings if required, then click Add. A routing policy will be created and members of this policy will use this IdP to sign in.