About SAML authentication
SAML (Security Assertion Markup Language) is an industry-standard specification for securely exchanging user authentication information between different systems. In addition to ZUNDA ID's built-in login methods (Google authentication, Microsoft authentication, and email authentication), you can use SAML 2.0 authentication to authenticate with external IdPs (Identity Providers) that support it.
By introducing SAML authentication, you can integrate with an IdP your organization already operates (such as Google Workspace, Microsoft Entra ID, or Okta) and log in to ZUNDA ID via single sign-on (SSO).
IdPs we've verified
We've verified compatibility with the following IdPs. Each IdP has its own setup procedure, so follow the instructions on the page that corresponds to the IdP you're using.
CloudGate Uno (published on the online community site "Kurage Plaza." If you're an administrator of CloudGate UNO, or belong to the department that manages it, you can register for access — please sign up to view it.)
Even if an IdP isn't listed above, you can use any IdP that complies with SAML 2.0 by configuring the required parameters, such as the ACS URL, entity ID, and IdP metadata. In that case, configure the settings by cross-referencing the IdP's own documentation with the corresponding settings on the ZUNDA ID side.
Supported features
ZUNDA ID's SAML authentication supports the following features.
-
Importing various user information
Based on the SAML assertion sent by the IdP, ZUNDA ID can import the email address, name (first and last), and display name. Combined with JIT (Just-In-Time) sign-up, an account is automatically created on the ZUNDA ID side the first time a user logs in, so you don't need to bulk-register users in advance.
-
SP Initiated login and IdP Initiated login
ZUNDA ID supports both "SP Initiated login," which starts a SAML login from the ZUNDA ID login screen, and "IdP Initiated login," which launches the app from the IdP's own dashboard (such as the Google Workspace app list, Microsoft MyApps, or the Okta dashboard).
-
Signing AuthnRequests
By attaching a digital signature to the authentication request (AuthnRequest) sent from ZUNDA ID to the IdP, you can detect tampering with the request. If the IdP requires signature verification, register the SP certificate issued by ZUNDA ID with the IdP.
-
Verifying the IdP certificate and, on the IdP side, the SP certificate
ZUNDA ID verifies the signature of the SAML response sent by the IdP using the registered IdP certificate. Likewise, the IdP can verify the signature sent by ZUNDA ID. This helps prevent impersonation and tampering that may occur during the authentication process.
Overall setup flow
We strongly recommend proceeding in the following order when introducing SAML authentication.
-
Login Method Recovery Settings (always do this first)
Before you start configuring SAML authentication, always issue and store a recovery key. This serves as a safeguard in case you're unable to log in due to a misconfiguration or an outage on the IdP side.
-
Creating and testing a SAML provider
Follow the setup procedure for your IdP to configure the required settings on both the ZUNDA ID side and the IdP side, and run a login test.
-
Enabling the SAML provider you created as a login method
Once the test succeeds, link the SAML provider to a domain so it can be used for actual user logins.
Login Method Recovery Settings
If a configured login method (SAML authentication, Google authentication, Microsoft authentication, etc.) becomes unavailable due to an outage on the IdP side, a misconfiguration, certificate revocation, or a similar issue, your account could end up locked out. To prevent this, always issue a recovery key and store it somewhere safe before enabling SAML authentication.
A recovery key can be issued offline, and even when SAML authentication is unavailable, a user with the Global Administrator role can use the recovery key to log in to ZUNDA ID and fix the configuration.
We recommend reviewing How to Configure Recovery Settings for Login Methods
and preparing this before configuring SAML authentication.
How to use the SAML provider you created as a login method
Once you've created and tested a SAML provider, you need to enable it as an actual login method. Because ZUNDA ID lets you link login methods per domain, configure the SAML provider you created for the target domain.
See How to Use the SAML Provider You Created as a Login Method
to proceed with this configuration.