These steps will guide you through setting up the single sign-on functionality between ADSelfService Plus and Cybozu.
Login to ADSelfService Plus as an administrator.
Navigate to Configuration → Self-service → Password Synchronizer..
Locate and click on Cybozu in the list of applications provided.
Click on the Download SSO Certificate link in the top-right corner of the screen.
Cybozu (Service Provider) configuration steps
Login to Cybozu with an administrator’s credentials.
Navigate to System Administration → Security → Login.
Navigate to SAML Authentication and toggle to enable.
Under SAML Authentication paste the URL, copied in Step 5 of Prerequisite, in the Login URL and Log out URL
Upload the downloaded certificate in Select a Certificate field.
You can save the configuration.
ADSelfService Plus (Identity Provider) configuration steps
Now, switch to ADSelfService Plus’ Cybozu configuration page.
In the Domain Name field, enter the domain name of your email address. For example, if you use email@example.com to log in to Cybozu, then mydomain.com is the domain name.
Enter Cybozu admin account SP-Identifier in the respective field.(https://<SP_Identifier>.cybozu.com)
Provide a Description in the respective field.
In the Available Policies field, click on the drop-down box and select the policies for which you wish to enable single sign-on.
Click Save and log out of ADSelfService Plus.
For Cybozu, single sign-on is supported for SP and IDP initiated flow.