Prerequisites
- A Company or an Enterprise account with Targetprocess
- Sign in to the Zoho One Admin Panel.
- Go to Marketplace, then use the search bar to find and install Targetprocess.
- Name your app and enter your Subdomain.
Note: Your Subdomain is the first part of your Targetprocess URL. If your URL is "zylker.tpondemand.com", your Subdomain will be "zylker".
- If you want to test the SAML configuration before allowing users to access Targetprocess, uncheck Display app to users.
- Click Add.
- Click Manage Application, then Single Sign-On.
- Click Service Provider Details to check and verify the SP details. You can also edit them, if needed.
- Click Identity Provider Details, then copy the Sign-in URL and the X.509 Certificate.
- Sign in to your Targetprocess account.
- Click your profile picture, then click Settings.
- Click Authentication and Security in the sidebar, then click the Single Sign-On tab.
- Check Enable Single Sign-on.
- Enter the IdP Sign-in URL in the Sign-on URL field and the IdP X.509 Certificate in the Certificate field.
- Click Save.
Just-in-time provisioning
Just-in-time (JIT) provisioning creates a Targetprocess account for users during their first SSO attempt, so you don't have to do it manually for each user.
To enable JIT provisioning:
- Sign in to your Targetprocess account.
- Click your profile picture, then click Settings.
- Click Authentication and Security in the sidebar, then click the Single Sign-On tab.
- Check Enable JIT Provisioning, then click Save.
Test the SAML connection
- Return to the Zoho One Admin Panel.
- Go to Applications, then click Targetprocess.
- Click Assign Users, choose yourself from the list, then click Assign.
- Click . If everything is working, you should be automatically signed in and taken to Targetprocess's homepage.
Enforce SAML SSO
After successfully testing SSO, you can enforce it for all users. Once this is done, your users will no longer be able to sign in using their Targetprocess credentials. To restrict users to SSO:
- Sign in to your Targetprocess account.
- Click your profile picture, then click Settings.
- Click Authentication and Security in the sidebar, then click the Single Sign-On tab.
- Check Disable login form, then click Save.
Make app visible to all users
After successfully testing the SSO, you can make Targetprocess available for all users to access from their My Apps pages.
To make Targetprocess visible to all users:
- Sign in to the Zoho One Admin Panel.
- Go to Applications, then click Targetprocess.
- Click Edit, check Display app to users, then click Update.
- You can now access Targetprocess from Zoho One's My Apps page.