Prerequisites:
When you're done with the prerequisites, add Zoho Vault as an application in:
- Okta
- OneLogin
Okta Integration
The integration follows three main steps:
- Adding Zoho Vault in Okta
- Configuring Okta details in Zoho Vault
- Assigning Zoho Vault to users in Okta
Adding Zoho Vault in Okta (IdP)
- Log in to your Okta account with admin privileges.
- Select Applications from the Applications tab.
- Click Add Application.
- Click Create New App.
- Set Platform as Web and Sign on method as SAML 2.0, then click Create.
- Enter the application name as Zoho Vault under General Settings, then click Next.
- Enter the service provider (Zoho Vault) details in Okta as described below, then click Next.
Note: Replace <YOUR-ORG-ID> with your unique ORG ID.
- Logout URL - https://accounts.zoho.com/logout/samlsp/<YOUR_ORG_ID>
- Audience URI (SP Entity ID): zoho.com
- Default RelayState: aHR0cHM6Ly92YXVsdC56b2hvLmNvbV9fSUFNX19ab2hvVmF1bHQ=
- Name ID format: EmailAddress
- Application username: Email
- Select I'm an Okta customer adding an internal app, then click Finish.
- Select Sign On, then click View Setup instructions. A new tab will open, containing the details required to configure SAML 2.0 in Zoho Vault.
Configuring Okta details in Zoho Vault
- Log in to your Zoho Vault account, then select Settings.
- Select AD/LDAP Integration from the Integrations section, then click SAML Configuration.
- Enter the identity provider details accordingly.
- To automatically create new Zoho accounts when users authenticate with Zoho Vault through Okta, enable Just in time provisioning.
- Click Save and Enable.
Assigning Zoho Vault to users in Okta
- Select Applications, then click Assign Applications in Okta.
- Under People, select the desired users and confirm assignments.
This completes the setup. Your users can now access Zoho Vault directly from Okta.
OneLogin Integration:
The integration follows two main steps:
- Adding Zoho Vault in OneLogin
- Configuring OneLogin details in Zoho Vault
Adding Zoho Vault in OneLogin
- Log in to your OneLogin account as an admin.
- Select Applications, then click Add app.
- Search for SAML test connector, then select SAML test connector (advanced).
- Set the Display name as Zoho Vault, then click Save.
- Select Configuration from the side panel, then enter zoho.com under the Audience field.
- Enter the following details in the corresponding fields.
RelayState - aHR0cHM6Ly92YXVsdC56b2hvLmNvbV9fSUFNX19ab2hvVmF1bHQ=
Recepient - https://accounts.zoho.com/signin/samlsp/<YOUR_ORG_ID>
ACS (Consumenr) URL Validator - https://accounts.zoho.com/signin/samlsp/<YOUR_ORG_ID>
ACS (Consumenr) URL - https://accounts.zoho.com/signin/samlsp/<YOUR_ORG_ID>
Logout URL - https://accounts.zoho.com/logout/samlsp/<YOUR_ORG_ID>
Note:
- Replace zoho.com with zoho.eu | zoho.in | zoho.com.cn | zoho.com.au to match your corresponding domain.
- Replace <YOUR-ORG-ID> with your unique ORG ID.
- Select More actions, then click SAML Metadata to download the metadata file. You will have to upload it to Zoho Vault later.
- Click Save.
- Select SSO from the side panel and make a note of these details to later add to Zoho Vault.
- Manage access to Zoho Vault and user privileges from the Access, Users, and Privileges tabs in the side panel, respectively.
- Click Save.
Configuring OneLogin details in Zoho Vault
- Log in to your Zoho Vault account, then select Settings.
- Select AD/LDAP Integration from the Integrations section, then click SAML Configuration.
- Enter the identity provider details you made a note of in step 9.
- To automatically create new Zoho accounts when users authenticate with Zoho Vault through OneLogin, enable Just in time provisioning.
- Click Save and Enable.
This completes the setup. Your users can now access Zoho Vault directly from OneLogin.