Add PingOne as an IdP and enable Custom Authentication

Add PingOne as an IdP and enable Custom Authentication

Custom authentication with PingOne enables SAML-based single sign-on (SSO) from PingOne to Zoho Directory. Once configured, users in your organization can access Zoho Directory from PingOne without signing in to Zoho Directory.

This article outlines the steps to configure custom authentication in Zoho Directory using PingOne as the Identity Provider (IdP).

Prerequisites

In Zoho Directory - Roles required to perform this action:
  1. Organization Owner
  2. Organization Admin
  3. Security Admin role

In PingOne: Configure SAML 

  1. In the PingOne admin console, go to Connections.
  2. Click Applications, then click the  icon.
  3. On the New Application page, click ADVANCED CONFIGURATION.
  4. Click Configure next to SAML.
  5. On the Create App Profile page, enter the Application Name. Provide a description and upload an icon, if needed (Optional).
  6. Click Save and Continue.
  7. On the Configure SAML Connection page select Manually Enter to provide app metadata.
  8. Enter the ACS URL and Entity ID in the respective fields.
  9. NotesYou can find the ACS URL and Issuer/Entity ID in Zoho Directory's Identity Providers page.
  10. Select urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress under SUBJECT NAMEID FORMAT.
  11. Enter a time duration in seconds (e.g., 3600) in the ASSERTION VALIDITY DURATION (IN SECONDS) field.
  12. NotesAssertion Validity Duration is how long a SAML assertion is valid for before it expires.
  13. Click Download Signing Certificate under SIGNING KEY and select the X509 PEM (.crt) format to be downloaded.
  14. Select Email Address under OUTGOING VALUE.
  15. Click Save and Close. You will be redirected to the Applications page.
  16. Turn on the toggle next to Zoho Directory application to enable the connection.
  17. From the Configuration tab, copy the SINGLE LOGOUT SERVICE URL and the SINGLE SIGNON SERVICE URL. You'll need to submit these URLs and the downloaded X509 PEM (.crt) certificate to add PingOne as an IdP in Zoho Directory.

In Zoho Directory: Add PingOne as an IdP

  1. Sign in to Zoho Directory, then click Admin Panel.
  2. Click Security in the left menu.
  3. Select Routing Policies, then go to the Identity Providers tab.
  4. Click Add identity Provider.
  5. Choose SAML as the SSO Protocol, then enter the name of your IdP in the IdP name field.
  6. Under Sign-in URL, paste the SINGLE SIGNON SERVICE URL copied from PingOne.
  7. Under Sign-out URL, paste the SINGLE LOGOUT SERVICE URL copied from PingOne.
  8. Upload the X509 PEM (.crt) file downloaded from PingOne under X509 certificate field.
  9. Click Add. PingOne will be added as an Identity Provider in Zoho Directory.

In Zoho Directory: Add Routing Policy to enable Custom Authentication

  1. On the same page, go to Routing Policies tab and click Add Policy.
  2. Enter a name for the policy, then select the members you want to apply the policy to.
  3. Select if any groups whose users should be excluded from the policy, even if they are part of the selected groups.
  4. Click Next.
  5. Under Authentication Modes, enable the Identity providers toggle, then select the IdP you added from the list.
  6. Click Next.
  7. Set Session Settings if required, then click Add. A routing policy will be created and members of this policy will use this IdP to sign in.