Zendesk - SSO configuration

Zendesk - SSO configuration

Idea
This documentation has been tested and approved by Kelvin Zero's team
Quote
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Zendesk using MPAS. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization.
Warning
To set up Multi-Pass with Zendesk, ensure you meet the following requirements
- Zendesk admin rights 
MPAS Admin rights
Important: Custom elements in URLs (like realm names) are case sensitive. Make sure to match the exact casing from your environment.


Zendesk - SSO Configuration



InfoAdmins can enable SAML single sign-on only for end users, only for team members (including light agents and contributors), or for both groups. You can create multiple SAML SSO configurations. Before you start, obtain the required information from your company's IT team.


Step 1 - Access Zendesk SSO Settings

  1. From your Zendesk dashboard, click the gear icon on the left sidebar to access the Admin Center.

  1. In Admin Center:
    1. Click Account
    2. Then navigate to Security → Single Sign-On
  2. Click Create SSO Configuration and choose SAML.
  1. in Zendesk Admin Center:
FieldValue
Configuration Namee.g. Multi-Pass
SAML SSO URLhttps://ca.auth.kzero.com/realms/<REALM_NAME>/protocol/saml
Certificate FingerprintFrom Multi-Pass certificate (see below how to find the certificate)
  1. Other settings:
    1. Show button when users sign in
      1. Button Name: Multi-Pass
    2. Under Team Member Authentication:
      1. Enable external authentication
      2. Select the name of the SSO you just created
    3. Click Save

Step 2 - Prepare Multi-Pass (IdP)

  1. Open Multi-Pass Dashboard

  1. Select your tenant.
  2. On the left side click on "Integrations"
  1. Click on "Applications" and select the box SAML.

  1. Complete the form based on information provided by Zendesk.
FieldValue
Client IDhttps://kelvinzero.zendesk.com/
Namezendesk
DescriptionTest SSO
Assertion Consumer Service URL
NameID Policy Formatemail


  1. Scroll down and copy the Certificate Fingerprint that you need to paste in the field called "Certificate fingerprint" in Zendesk
  1. Finalize by clicking on "Add integration"

Verification and completion in the advanced console

  1. In order to reach the advanced console, from your dashboard, click on "advanced console" located in the left side. 
  1. Click on client and search for the new entry that you just created
  1. Make sure the fields are correctly completed : 
    1. Settings tab, general settings section : 
FieldValue
Client ID
https://<YOUR_SUBDOMAIN>.zendesk.com
Namee.g. zendesk
Descriptione.g. Test SSO
Always Display in UION
  1. Scroll down to the access settings section and complete the fields : 
FieldValue
Home URLhttps://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/<APP_Name>
Valid Redirect URIshttps://<YOUR_SUBDOMAIN>.zendesk.com/access/saml/
IDP-Initiated SSO URL Name<APP_Name> (e.g. zendesk)
  1. Move to the section SAML Capabilities :
SettingValue
Name ID Formatemail
Force POST BindingON
Include AuthnStatementON
Include AuthnStatement
  ON
  1. Go to the Signature and Encryption : 
    1. Sign assertions has to be switched to ON 
  2. Click Save and go to the keys tab :
    1. Both parameters have to be switched to OFF
  3. Finally move to the Advanced tab and complete : 
FieldValue
Assertion Consumer Service POST Binding URLSame as Valid Redirect URI (https://<SUBDOMAIN>.zendesk.com/access/saml/)

    • Related Articles

    • SAML SSO Integration Guide

      This guide provides an overview of how to configure SAML Single Sign-On (SSO) between Multi-Pass and a third-party Service Provider (SP). Multi-Pass acts as the Identity Provider (IdP) in this federation model. Multi-Pass is working on SCIM support ...
    • Notion - SSO configuration

      Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a ...
    • Vanta - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Vanta using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • Dynatrace - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Dynatrace using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • Addigy - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Addigy using MPAS. SSO simplifies user authentication by allowing access to multiple ...