SSO Field Guide
Introduction
SSO Integrations
SSO Requires a Vanity URL to get started
Zoom SSO works with any SAML 2.0 identity provider
Zoom administrators can manage user profile information and licensing through SAML response mapping or SCIM integrations
Zoom administrators can manage user account status through SCIM, but not SAML
Limited identity providers offer SCIM for Zoom
SCIM requires an associated domain to automatically provision users
The following SSO integrations are documented
Provider Documentation
Zoom Documentation
Supports SCIM
On-premises Active Directory can use the AD Sync Tool instead of SCIM
Identity providers can even authenticate meeting participants that don't have a Zoom account
Changing the identity provider requires re-configuring SSO within Zoom
Customers with sub-accounts can configure SSO from the master or sub-account
SSO Settings & Security
Zoom supports signed login and logout SAML requests
Zoom supports encrypted SAML assertions when authenticating
Zoom administrators can enforce automatic logout after a defined length of time
SAML response logs can be saved for troubleshooting
Provisioning at sign-in can create accounts instantly and is the easiest provisioning option
Provisioning prior to sign-in requires pre-created accounts with an SSO login type
A domain must be associated and managed to enforce SSO authentication
Specified users can be exempt from enforced SSO authentication
Mobile and desktop clients can be configured to require users to use SSO authentication
Office 365 users can automatically sign in to the Zoom for Outlook add-in using SSO credentials
SAML Response Mapping
Fundamentals: SAML Attributes and Values
SAML Attribute
SAML Value
Basic Mapping: Profile Information
Default license type only applies to brand new users
A default license type of None will not allow new users to authenticate unless advanced mapping is configured to assign a license
Most basic mappings will re-apply on login, unless otherwise specified
Phone number mappings should include a country code and area code if outside the United States
Each user can have up to three phone numbers and one fax number mapped to their profile
Profile pictures must be mapped from either a publicly accessible URL or encoded with Base64
Employee Unique ID
Advanced Mapping: Licenses, Add-ons, and Access
Advanced mapping applies every time a user authenticates
Advanced mapping allows multiple SAML attributes and values per category
Advanced mapping applies licenses from the top-down when multiple attributes are asserted
Webinar and Large Meeting mappings can share a common value to apply both add-ons
Users can be added to multiple User Groups using one SAML value
Specified users and User Groups can be exempt from specific SAML mappings
Auto Mapping automatically assigns users to a User, Channel, or IM group named after their asserted SAML value if the value is not previously mapped to a group
SAML Attribute
SAML Value
Does Zoom Group already exist?
Result
Zoom supports up to five custom SAML attributes
Mapping users to a sub-account will only apply a meeting license and add-ons
Troubleshooting SSO
Using SAML Response Logs to Troubleshoot
Most authentications will display in the response logs
Response logs can tell you if your configuration is incorrect or your certificate is outdated
Response logs tell you which SAML values and attributes are being asserted
Response Logs include an error code and brief explanation, if unsuccessful
Web Tracking ID Errors
SCIM Errors
User Not Exist or Not Belong to this Account
You Can’t Add Paid Users
Using SCIM Logs to Troubleshoot User Provisioning
Data Flows and Authentication
SAML Authentication
SSO Web Login Token
Client Login Token
Last updated
Was this helpful?

