Add Microsoft Entra ID as an IdP and enable Custom Authentication

Add Microsoft Entra ID as an IdP and enable Custom Authentication

Custom authentication with Microsoft Entra ID enables SAML-based single sign-on (SSO) from Microsoft Entra ID to Zoho Directory. Once configured, users in your organization can access Zoho Directory from Microsoft Entra ID without signing in to Zoho Directory.

This article outlines the steps to configure custom authentication in Zoho Directory using Microsoft Entra ID as the Identity Provider (IdP).

Prerequisites

In Zoho Directory - Roles that can perform this action:
  1. Organization Owner
  2. Organization Admin
  3. Security Admin role

In Microsoft Entra ID: Add Zoho Directory as an enterprise application

  1. Sign in to Microsoft Entra admin center.
  2. Click Entra ID in the left navigation menu, then click Enterprise apps.
  3. Click New application, then click Create your own application.
  4. Enter Zoho Directory under What's the name of your app?, choose Integrate any other application you don't find in the gallery, then click Create
    The app will be created, and you will be redirected to its Overview tab.
  5. Click Get started under Set up single sign on, then click SAML.
  6. Click Edit against Basic SAML Configuration.
  7. Click Add identifier and enter the Issuer copied from Zoho Directory.
  8. Click Add reply URL and enter the ACS URL copied from Zoho Directory.
  9. NotesYou can find the Issuer and ACS URL in the Zoho Directory's Add Identity Providers page.
  10. Click Save, then click    on the top-right corner.
  11. Under SAML certificates, click Download against Certificate (Base64).
  12. Under Set up Zoho Directory, copy the Login URL and Logout URL to your clipboard. You'll need to submit these URLs and the downloaded certificate to add Microsoft Entra ID as an IdP in Zoho Directory.

In Zoho Directory: Add Microsoft Entra ID as an IdP

  1. Sign in to Zoho Directory, then click Admin Panel.
  2. Click Security on the left menu.  
  3. Select Routing Policies, then go to the Identity Providers tab.
  4. Click Add Identity Provider. 
  5. Choose SAML as the SSO Protocol, then enter the name of your IdP in the IdP name field.
  6. Paste the Login URL copied from Microsoft Entra ID under Sign-in URL and Logout URL under Sign-out URL.
  7. Upload the Base64 certificate from Microsoft Entra ID under the X509 certificate field.
  8. Click Add. Microsoft Entra ID will be added as an identity provider in Zoho Directory

In Zoho Directory: Add Routing Policy to enable Custom Authentication

  1. On the same page, go to Routing Policies tab and click Add Policy.
  2. Enter a name for the policy, then select the members you want to apply the policy to.
  3. Select if any groups whose users should be excluded from the policy, even if they are part of the selected groups.
  4. Select the priority of this policy with other routing policies.
  5. Click Next.
  6. Under Authentication Modes, enable the Identity providers toggle, then select the IdP you added from the list.
  7. Click Next.
  8. Set Session Settings if required, then click Add. A routing policy will be created and members of this policy will use this IdP to sign in.