Zoho One - SSO configuration

Zoho One - SSO configuration

Idea
This documentation has been tested and approved by Kelvin Zero's team
Quote
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Zoho One using MPAS. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization.
Warning
In order to complete this integration please make sure you have the following : 
- Zoho One Account: Admin rights
- MPAS: Admin rights and SSO metadata
- Domain Verification: Your domain must be verified in Zoho One prior to the SSO configuration.
Important: Custom elements in URLs (like realm names) are case sensitive. Make sure to match the exact casing from your environment.


Configuring Zoho One


  1. On your Zoho One dashboard, click on the "Setup" icon located top right of your screen 
  2. In the left menu, select "Security" and then "Custom Authentication"
  1. Click on "Add IdP"
  1. Complete the fields and click on "Save"
  2. Now we need to start the configuration of MPAS, follow this link : dashboard.kzero.com
  3. Select your deployment, and click on "Admin Console"
  4. In the Admin Console, select "Clients" and fill the required fields, click on "Next" then Click on "Save"


  1. Complete the fields in the different sections
  1. Home URL = https://ca.auth.kzero.com/realms/<REALM NAME>/protocol/saml/clients/zoho
  2. Valid redirect URIs = https://desk.zoho.com/ - https://accounts.zoho.com/signin/sam[...]
  3. IDP-Initiated SSO URL name = zoho
  4. Name ID format = email 
  5. Sign assertions = ON

  1. Click on "Realm Setting" and then on "Keys"

  1. Select certificate and Copy the text, paste it in a note to get a .txt file.
  2. Go back to Zoho One and complete the different fields
    1. Signin-url: https://ca.auth.kzero.com/realms/<REAL NAME>/protocol/saml
    2. signout-url: https://ca.auth.kzero.com/realms/<REALM NAME>/protocol/openid-connect/logout?redirect_uri=https%3A%2F%2Fdesk.zoho.com%2Fportal%2Fdeccanpl%2F
    3. Change-password: https://ca.auth.kzero.com/realms/<REALM NAME>/protocol/saml

AlertOnce Zoho One is integrated with MPAS, make sure you assign the SSO setting to the required Groups and/or Users in your Zoho Admin Console

    • Related Articles

    • Zoho Desk - CIAM Passwordless configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up MPAS as the CIAM passwordless authentication method for your customers. This integration enhances security and ...
    • Auvik - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Auvik using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • Odoo - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Odoo using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • BambooHR - SSO Configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Bamboo HR using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • Datadog - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Datadog using MPAS. SSO simplifies user authentication by allowing access to multiple ...