- Sign in to the Zoho One Admin Panel.
Go to Marketplace, then use the search bar to find and install Salesforce.
- Name your app and enter your Salesforce.com Organization ID.
Note: You can find your Salesforce.com Organization ID under Company Information in your Salesforce settings. - If you want to test the SAML configuration before allowing users to access Salesforce, uncheck Display app to users.
- Click Add.
- Click Manage Application, then Single Sign-On.
- Click Service Provider Details to check and verify the SP details. You can also edit them if needed.
Click Identity Provider Details, then download the IdP Metadata and the X.509 Certificate. Make a note of the Issuer, the Sign-in URL, and the Sign-out URL.
- Sign in to your Salesforce account.
- Go to your account's Single Sign-On Settings.
- Click Edit and check SAML Enabled.
- You can choose to configure SAML manually or automatically.
- If you choose to configure automatically, click New from Metadata File and upload the IdP Metadata file.
- If you choose to configure manually, click New. Fill in the following fields:
- Enter "Zoho One" in the Name field.
- Enter the Issuer in the Issuer field.
- Upload the X.509 certificate under Identity Provider Certificate.
- Enter the Sign-in URL in the Identity Provider Login URL field.
- Enter the Sign-out URL in the Custom Logout URL field.
- Click Save.
Just-in-time provisioning
Just-in-time (JIT) provisioning creates a Salesforce account for users during their first SSO attempt, so you don't have to do it manually for each user.
To enable JIT provisioning:
- Sign in to your Salesforce account.
- Go to your account's Single Sign-On Settings.
- Under SAML Single Sign-On Settings, click Edit next to the Zoho One SAML configuration.
- Check User Provisioning Enabled and choose Standard.
Note: While Standard JIT Provisioning would satisfy most users' needs, you might want to choose Custom SAML JIT with Apex handler if you need more control over account provisioning.
Test the SAML connection
- Return to the Zoho One Admin Panel.
- Go to Applications, then click Salesforce.
- Click Assign Users, choose yourself from the list, then click Assign.
Click
. If everything is working, you should be automatically signed in and taken to Salesforce's homepage.
Make app visible to all users
After successfully testing the SSO, you can make Salesforce available for all users to access from their My Apps pages.
To make Salesforce visible to all users:
- Sign in to the Zoho One Admin Panel.
- Go to Applications, then click Salesforce.
- Click Edit, check Display app to users, then click Update.
You can now access Salesforce from Zoho One's My Apps page.