Prerequisites
- A Sumo Logic Enterprise account
- Sign in to the Zoho One Admin Panel.
Go to Marketplace, then use the search bar to find and install Sumo Logic.
- Name your app and enter your Sumo Logic Deployment.
Note: Your Deployment is the second part of your Sumo Logic URL. If your URL is "service.us2.sumologic.com", your Deployment will be "us2". - Enter "1234" under Unique ID.
- If you want to test the SAML configuration before allowing users to access Sumo Logic, uncheck Display app to users.
- Click Add.
- Click Manage Application, then Single Sign-On.
- Click Service Provider Details to check and verify the SP details. You can also edit them, if needed.
Click Identity Provider Details, then copy the Issuer, the Sign-in URL, the Sign-out URL, and the X.509 Certificate.
- Sign in to your Sumo Logic account.
- Click Administration in the sidebar, then click Security.
- Click SAML, then click Add Configuration.
- Enter "Zoho One" in the Configuration Name field, the IdP Issuer in the Issuer field, and the IdP X.509 Certificate in the X.509 Certificate field.
- Choose Use SAML Subject under Attribute Mapping.
- Check Logout Page, then enter the IdP Sign-out URL in the Logout URL field.
- Click Add.
- Click the newly added Zoho One configuration and copy the value after "https://service.au.sumologic.com/sumo/saml/login/" from the Authentication Request.
- Return to the Zoho One Admin Panel, click Applications, then click Sumo Logic.
- Click Single Sign-On, then click Service Provider Details. Under Unique ID, replace "1234" with the value copied in step 8.
- Click Save.
Just-in-time provisioning
Just-in-time (JIT) provisioning creates a Sumo Logic account for users during their first SSO attempt, so you don't have to do it manually for each user.
To enable JIT provisioning:
- Sign in to your Sumo Logic account.
- Click Administration in the sidebar, then click Security.
- Click SAML, then click the Zoho One configuration.
- Click , then check On Demand Provisioning.
- Enter "firstName" in the First Name field, "lastName" in the Last Name field, and enter the Sumo Logic RBAC roles you want to assign when user accounts are provisioned in the On Demand Provisioning Roles field (The roles must exist in Sumo Logic).
- Click Save.
- Sign in to the Zoho One Admin Panel.
- Go to Applications, then click Sumo Logic.
- Click Single Sign-On, then Service Provider Details.
- Under Attribute Mapping, enter the following details:
- Enter "firstName" under Attribute Name, then select First Name under Attribute Value.
- Click , enter "lastName" under Attribute Name, then select Last Name under Attribute Value.
- Click Save.
Test the SAML connection
- Return to the Zoho One Admin Panel.
- Go to Applications, then click Sumo Logic.
- Click Assign Users, choose yourself from the list, then click Assign.
- Click . If everything is working, you should be automatically signed in and taken to Sumo Logic's homepage.
Enforce SAML SSO
After successfully testing SSO, you can enforce it for all users. Once this is done, your users will no longer be able to sign in using their Sumo Logic credentials. To restrict users to SSO:
- Sign in to your Sumo Logic account.
- Click Administration in the sidebar, then click Security.
- Click SAML, then toggle Require SAML Sign In.
Make app visible to all users
After successfully testing the SSO, you can make Sumo Logic available for all users to access from their My Apps pages.
To make Sumo Logic visible to all users:
- Sign in to the Zoho One Admin Panel.
- Go to Applications, then click Sumo Logic.
- Click Edit, check Display app to users, then click Update.
- You can now access Sumo Logic from Zoho One's My Apps page.