If you're a Zoho One user:
- Sign in to Zoho One, then click Directory in the left menu.
- Go to Marketplace, then click Browse Applications.
- Use the search bar to find and install Igloo.
If you're a Zoho Directory user:
- Sign in to Zoho Directory, then click Admin Panel in the left menu.
- Go to Applications, then click Add Application.
- Use the search bar to find and add Igloo.
- Name your app and enter the Domain Name.
Note: Your Domain Name is the first part of your Igloo URL. If your URL is "zylker.igloo.com", your Domain Name will be "zylker".
- Click Add.
- Click the Single Sign-On tab.
- Click Service Provider Details to check and verify the SP details. You can also edit them if needed.
- Click Identity Provider Details, then copy the Sign-in URL and the X.509 Certificate.
- Sign in to Igloo as an administrator.
- Click in the top right corner, then click Sign In Settings under Membership.
- Click Configure SAML Authentication.
- In the General Configuration section:
- Enter the Connection Name as "Zoho Directory".
- Paste the previously-copied Sign-in URL in the IdP Login URL field.
- Paste the previously-copied X.509 Certificate in the Public Certificate field.
- Leave the other fields in their default values.
- In the Response and Authentication Configuration section:
- In the Identity Provider dropdown menu, select Other.
- In the Identifier Type dropdown menu, select Email Address.
- Leave the other fields in their default values.
- Click Save.
Just-in-time provisioning
Just-in-time (JIT) provisioning creates an Igloo account for users during their first SSO attempt, so you don't have to do it manually for each user.
To enable JIT provisioning:
- Sign in to Igloo as an administrator.
- Click in the top right corner, then click Sign In Settings under Membership.
- Click Configure SAML Authentication.
- In the User creation on Sign in section, select Create a new user in your site when they sign in (Users will be added to manage members on sign in).
- Click Save.
Test the SAML connection
- Return to the Zoho Directory Admin Panel.
- Go to Applications, then click Igloo.
- Click Assign Users, choose yourself from the list, then click Assign.
- Click on the icon next to the app's name. If everything is working, you should be automatically signed in and taken to Igloo's home page.
Enforce SAML SSO
After successfully testing SSO, you can enforce it for all users. Once this is done, your users will no longer be able to sign in using their Igloo credentials. To restrict users to SSO:
- Sign in to Igloo as an administrator.
- Click in the top right corner, then click Sign In Settings under Membership.
- Click Configure SAML Authentication.
- In the Sign in Settings section, select Redirect all users to IdP.
- Click Save.