Setting up ZEN Master Azure SSO

This section includes instructions on how to register ZEN Master as an SSO app on Azure and configure the connection between ZEN Master and Azure. To complete this process, you need to login as an Admin on both the Azure side and the ZEN Master side. It is, therefore, recommended to have both open in parallel.

To setup ZEN Master Azure SSO:

  1. In Azure, go to Identity > Azure Active Directory > App Registrations.

  2. Click New Registrations.

  3. In the Name field, enter a name for the SSO app. This name will be displayed to the users when they use Azure as an SSO portal. For example, "ZEN Master SSO".

  4. Under Supported account types, specify who can access the ZEN Master SSO app. In this case, it is recommended to select the Account in this organizational directory option.

  5. In ZEN Master, go to Account Management > Single Sign-On.

  6. Click +Add.

  7. In the Name field, enter a name for this SSO connection. This is the name that will be displayed on the Azure button in the ZEN Master Sign In portal. 

  8. At the bottom of the screen, copy the Callback URL.

  9. Back in Azure, paste the copied Callback URL into the Redirect URI field.

  10. Click Register.
    The following screen is displayed with the connection strings.

  11. Copy the Application (client) ID from Azure and paste it to the Client ID field in ZEN Master.

  12. In Azure click Endpoints at the top.

  13. Copy and paste the following credentials from Azure to ZEN Master:

  14. In Azure, go to Certificates & secrets.

  15. Under Client Secrets, click New Client Secret.

  16. In the Description field, enter any name for the client secret. For example, "ZEN Master".

  17. Under Expires, select the desired expiration time.

  18. Click Add.

  19. Copy the secret by clicking the Copy button.

  20. In ZEN Master, paste the copied secret into the Client Secret field.

  21. If you to manually register Azure AD users to ZEN Master (see https://zixidocumentation.atlassian.net/wiki/spaces/SSG/pages/1538064483 section) before granting access, select the Allow pre-registered users only checkbox. The registration is simple and only involves entering the user's email.

  22. In ZEN Master, click Save.
    The newly created Azure SSO is added to the list of SSO profiles. The users defined in the Azure AD will be able to connect to ZEN Master by selecting the newly created SSO option under Sign In With. During the first connection you will be required to provide permission to connect through Azure to ZEN Master. As an administrator, you can select Consent on behalf of your organization option, which will not require additional consent by the other users.

    However, if you have selected the Allow pre-registered users only option you will need to manually pre-register the users by following the instructions below.