About this page
This page explains how to enable a SAML provider you've created as an actual login method. It assumes you've already created the SAML provider and successfully run a login test.
ZUNDA ID lets you link login methods on a per-domain basis. For example, you can configure things so that users belonging to the @example.com domain are only allowed to use SAML authentication.
Before configuring this, always complete How to Configure Recovery Settings for Login Methods. If you proceed without a recovery key, you risk being locked out in case of a misconfiguration.
Setup steps
Open the details screen of the SAML provider you created, and switch Status to ON to activate the provider
You can only select a provider as a login method while its status is ON. If you haven't tested a provider yet, first run a login test using the Test button on its details screen and confirm it succeeds before activating it.
Open the Domain Settings screen, and select the domain you want to link the login method to
ZUNDA ID lets you configure the available login methods separately for each domain. If you use multiple domains, select and configure each domain you want to apply SAML authentication to.
On the domain details settings screen, select the login methods you want to allow for users of this domain
Checking the SAML provider you created allows users of that domain to log in using SAML authentication. You can also allow multiple login methods at the same time (for example, SAML authentication and Google authentication). If your security policy requires restricting users to a specific authentication method, uncheck the other login methods.
Verifying it works
After clicking Save, confirm that a user belonging to that domain can actually log in. Open the ZUNDA ID login screen in a different browser or an incognito window, and confirm you can log in using the SAML authentication you configured — this completes the setup.
We recommend performing this verification in a session independent of your current administrator session. That way, even if there's a misconfiguration, your current administrator session remains intact, so you can still go back and correct the configuration.