Configuring Zoom SSO with ADFS

 

You can configure your account to login via Single Sign-On (SSO) with Active Directory Federation Services (ADFS). You can use SAML mapping to assign users licenses, groups, and roles based on their ADFS configuration. Read more about Single Sign-On.

This article covers:

Prerequisites for SSO with ADFS

Note: Without an approved Associated Domain, users will need to confirm to being provisioned on the account through an email automatically sent to them. Provisioning will take place without email confirmation for any users falling under an approved domain.

How to configure SSO for ADFS in Zoom

  1. Find and download/view your ADFS XML metadata at https://[SERVER]/FederationMetadata/2007-06/FederationMetadata.xml
    *[SERVER]: your ADFS server (adfs.example.com)
  2. From the Zoom Admin page, click on Single Sign-on to View the SAML tab.
  3. Enter the following information into the SAML tab options:

How to configure SSO for Zoom in ADF

  1. Login to your ADFS server.
  2. Open ADFS 2.0 MMC
  3. Add a Relying Party Trust
    Select Import data about the relying party published online or on a local network
    Federation metadata address:   https://YOURVANITY.zoom.us/saml/metadata/sp 
  4. Add a display name ("Zoom") and finish the Wizard with default settings
  5. Add two claim rules:

Once you have completed the configuration steps, any user in your active directory should be able to login, based on the configuration you have set. To test, visit http://YOURVANITY.zoom.us and select Login. 

Troubleshooting

Unable to log in using Google Chrome or Firefox

If you are unable to log in using Chrome or Firefox, and are seeing an 'Audit Failure' event with "Status: 0xc000035b" in the Event Viewer on the ADFS server, you will need to turn off Extended Protection. Chrome and Firefox do not support the Extended Protection of ADFS (IE does).

  1. Launch IIS Manager
  2. In the left panel, navigate to Sites > Default Web Site > ADFS > LS
  3. Double-click Authentication icon
  4. Right-click Windows Authentication
  5. Select Advanced Settings
  6. Turn OFF Extended Protection

How to generate and update the X509 certificate

If you are prompted to update your Identity Provider certificate in the Zoom portal, please refer to the instructions on the Microsoft Support site on how to generate a new certificate in ADFS. Once you have the new certificate, edit the SSO configuration on the Zoom portal and replace the existing certificate with the newly generated version.