Add miniOrange as an IdP and enable Custom Authentication

Add miniOrange as an IdP and enable Custom Authentication

Custom Authentication with miniOrange enables SAML-based single sign-on (SSO) from miniOrange to Zoho Directory. Once configured, users in your organisation can access Zoho Directory from miniOrange without signing in to Zoho Directory.

This article outlines the steps to configure custom authentication in Zoho Directory using miniOrange as the Identity Provider (IdP).

Prerequisites

In Zoho Directory - Roles that can perform this action:
  1. Organization Owner
  2. Organization Admin
  3. Security Admin role

In miniOrange: Configure SAML 

  1. Sign in to miniOrange.
  2. Click Apps in the left menu, then click Add Application.
  3. Under Choose Application, select SAML/WS-FED from the All Apps dropdown.
  4. In the displayed list of apps, search and select Zoho.
  5. Under the Basic tab, provide a Display Name for the app.
  6. Enter the SP Entity ID or Issuer and ACS URL in the respective fields.
  7. Notes You can find the Issuer and ACS URL in Zoho Directory's Identity Provider page.
  8. Click Next to go to the Attributes page.
  9. Select E-Mail Address under Name ID.
  10. Select urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress under NameID Format.
  11. Click Next to go to the Policies tab. You need to save the application first to assign it to the required groups and configure the desired login policies.
  12. Go to the Metadata tab, then click miniOrange as IdP.
  13. Copy the SAML Login URL, and SAML Logout URL, then click Download Certificate. You'll need to submit these URLs and the downloaded certificate to add miniOrange as an IdP in Zoho Directory.

In Zoho Directory: Add miniOrange as an IdP

  1. Sign in to Zoho Directory, then click Admin Panel.
  2. Click Security in the left menu.
  3. Select Routing Policies, then go to the Identity Providers tab.
  4. Click Add identity Provider.
  5. Choose SAML as the SSO Protocol, then enter the name of your IdP in the IdP name field.
  6. Under Sign-in URL, paste the SAML LOGIN URL copied from miniOrange.
  7. Under Sign-out URL, paste the SAML LOGOUT URL copied from miniOrange.
  8. Upload the Certificate downloaded from miniOrange under X509 certificate field.
  9. Click Add. miniOrange will be added as an Identity Provider in Zoho Directory.

In Zoho Directory: Add Routing Policy to enable Custom Authentication

  1. On the same page, go to Routing Policies tab and click Add Policy.
  2. Enter a name for the policy, then select the members you want to apply the policy to.
  3. Select if any groups whose users should be excluded from the policy, even if they are part of the selected groups.
  4. Click Next.
  5. Under Authentication Modes, enable the Identity providers toggle, then select the IdP you added from the list.
  6. Click Next.
  7. Set Session Settings if required, then click Add. A routing policy will be created and members of this policy will use this IdP to sign in.