Configuring Zoom with OneLogin
Prerequisites for OneLogin
- to be an owner or administrator of Zoom
- Education or Business accounts with approved vanity URL
- access
In the absence of a domain associated with the account, users will be sent an email confirming that they are provisioned on the account. For any users whose domain is approved, provisioning will occur without requiring an email confirmation.
How to configure Zoom with OneLogin
- Go to https://app.onelogin.com/apps to access your OneLogin Admin account
- Click Add App.
- Select the Zoom application by searching for “Zoom” in the provided search field.
- Click Save after you have edited your display name (if necessary).
- Once saved, open the configuration tab and enter only your Vanity URL subdomain, then click Save. Here is an example of a Vanity URL: https://lukehaselwood.zoom.us
- The Zoom OAuth button is located under Configuration, under Authenticate.
- Visit Zoom’s website and log in.
- Select Advanced and Single Sign-On under the Navigation panel.
- Navigate to the Zoom application’s SSO tab in OneLogin as well. You will need to match the settings as follows:
- This is the URL for the Zoom sign-in page on OneLogin’s SAML 2.0 Endpoint (HTTP)
Important: In the URL, http-redirect should be used as the binding.“https://app.onelogin.com/trust/saml2/http-post/sso/####”
Should be changed to:
“https://app.onelogin.com/trust/saml2/http-redirect/sso/####” - There are two options for Zoom Sign-out: (HTTP) > OneLogin SLO Endpoint (HTTP)
- OneLogin Issuer URL > Zoom Issuer
- This is the URL for the Zoom sign-in page on OneLogin’s SAML 2.0 Endpoint (HTTP)
- Under the OneLogin X.509 Certificate, select the View Details link for the Zoom Identity provider certificate (shown above). You should copy the text shown in the X.509 certificate field between the Begin and End certificates for Zoom Identity Provider and paste it into the appropriate field on Zoom Identity Provider
—-BEGIN CERTIFICATE—–
COPY THIS TEXT
—–END CERTIFICATE—–
-
- The Zoom Binding should be set to HTTP-Redirect
- Please select the SAML Response Mapping option if you need to set up SAML Response Mapping in your application, adding or changing the default user type, etc.
- Then click Save.
- In order to make sure your users can access Zoom, you’ll need to configure OneLogin.
- Log in by visiting your Vanity URL. OneLogin will be redirected to your Vanity URL. When a user signs in, Zoom creates an account, pulls first and last names if available, and logs them in.
How to enable the API integration for Zoom
- Connect to the Zoom API over OAuth by selectingg Authenticate next to API Connection. This allows OneLogin users to be provisioned or de-provisioned to Zoom.
- To authorize access to OneLogin, sign in to Zoom and click Allow.
- Make sure you have the ability to edit account settings by logging in as an administrator.
- In OneLogin, click Provisioning.
- Click Enable provisioning by workflow to enable it.
- Check the check boxes for the options you want the API to work with under Require admin approval before this action is performed.
- Save your changes.