Custom Authentication enables SAML-based single sign-on (SSO) from your preferred identity provider (such as
Okta and
OneLogin) to Zoho One. With SSO, you and your employees can sign in to your identity provider and access Zoho One directly, without having to sign in to Zoho One. Custom Authentication can be used with any identity provider that supports SAML.
To set up custom authentication:
- Sign in to your Zoho One Admin Panel.
- Go to Security, then click the Custom Authentication tab.
- Click Setup Now.
- Enter the following details obtained from your Identity Provider (IdP):
- Sign-in URL: The URL to which the user will be redirected when they try to sign in to Zoho.
- Sign-out URL: The URL to which the user will be redirected after signing out of Zoho.
- Change Password URL: The URL to which the user will be redirected if they try to change their Zoho account's passwords.
Note: Admins will not be redirected to the IdP's Change Password URL, and will be allowed to change their password in Zoho.
- Verification Certificate: The certificate with which Zoho can check the digital signature on the IdP's authentication.
Note: Only base-64 encoded .CER, .CRT, .CERT, or .PEM files will be accepted.
- Click Save, then Yes, Confirm. Once SAML is configured, users will no longer need to use their Zoho One password to sign in. They will only need to enter their email address in Zoho One's sign-in page, and will automatically be redirected to your IdP for authentication. Alternatively, they can also sign in to your IdP first and access Zoho One from there.