Prerequisites
To enable Single Sign-on for Zoho Apps, SAML Authentication configuration to be done in Zoho Accounts.
A. Configuration in Zoho Account
A.1. Login to Zoho Account. Go to Organization > SAML Authentication to add SAML settings. Click on Download Metadata and open the file.
A.2. Right click on the downloaded metadata file and open with notepad or any other text editor, then copy Entity ID and ACS URL from the downloaded metadata. These will be used to add Zoho application in Zaperon. Refer to section B.3.
A.3. Click on Setup Now and click Submit after entering all the details.
B. Add Application in Zaperon
B.1. In the Admin Dashboard, click Application > Add Application.
B.2. Search for Zoho in application catalogue and select the app.
B.3. Enter details in SAML settings and click Next.
B.4 . In Attribute Mapping tab, select in SAML Attribute Format value as Email Address and User Attribute value as Business Email for Name ID SAML Attribute and click Next. A new custom attribute can be created by clicking on Add Custom Attributes button.
B.5. In Event Tracking tab, click Add Resource to enable tracking of different events of applications. For more details on event tracking Refer to this section. and click Submit.
B.6. A Single Sign-on Configuration popup will appear. Copy Sign-in URL, Sign-out URL and download certificate. These will be used to configure SAML in Zoho Accounts. Follow instructions in section A.3.
B.7. You will see Zoho app has been added in the applications table.
C. Enable partial SSO in Zoho
C.1. Login to your Zoho Directory and click Admin Panel in sidebar.
C.2. Click Groups in sidebar and then click Add Group.
C.3. Enter group name and add members/users you want to exclude from SSO and then click Add.
C.4. Click on Security in sidebar > Custom Authentication tab and then click Add IDP.
C.5. Click on add button and select the group you created.