このガイドでは、Cloudflare One で Zoom ↗ を SAML アプリケーションとして設定する手順を説明します。
- Cloudflare One に設定済みの ID プロバイダー
- Zoom Business、Education、または Enterprise アカウントの管理者権限
- Zoom アカウントに設定済みの associated domain ↗
- Zoom アカウントに設定済みの vanity URL ↗
- Cloudflare ダッシュボード ↗ で Zero Trust > Access controls > Applications を開きます。
- Create new application > SaaS application を選択します。
- Application で Zoom を選択します。
- 認証プロトコルは SAML を選択します。
- Add application を選択します。
- 次の欄を入力します。
- Entity ID:
https://<your-vanity-url>.zoom.us - Assertion Consumer Service URL:
https://<your-vanity-url>.zoom.us/saml/SSO - Name ID format: Email
- Entity ID:
- Access Entity ID or Issuer、Public key、SSO endpoint をコピーします。
- アプリケーションの Access ポリシー を設定します。
- アプリケーションを保存します。
- Zoom で Advanced > Single Sign-On を開きます。
- Vanity URL で、SSO を設定する vanity URL を選択します。
- 次の欄を入力します。
- Sign in page URL: Cloudflare One のアプリケーション設定にある SSO endpoint
- Identity Provider Certificate: Cloudflare One のアプリケーション設定にある Public key
- Service Provider (SP) Entity ID:
yourvanityurl.zoom.us(https://は付けません) - Issuer (DP Entity ID): Cloudflare One のアプリケーション設定にある Access Entity ID or Issuer
- Binding で http-redirect を選択します。
- Signature Hash Algorithm で SHA-256 が選択されていることを確認します。
- Security で Sign SAML request と Sign SAML logout request をオフにします。
- Save Changes を選択します。
- Advanced > Security を開きます。
- Sign-in Methods で Allow users to sign in with Single Sign-On (SSO) がオンになっていることを確認します。
シークレットブラウザーウィンドウを開き、Zoom の vanity URL にアクセスして Sign in を選択します。Cloudflare Access のログイン画面にリダイレクトされ、ID プロバイダーでのサインインを求められます。
成功したら、次の手順で associated domain のユーザーに SSO を必須にできます。
- Zoom で Advanced > Security を開きます。
- Sign-in Methods で Require users to sign in with SSO if their e-mail address belongs to one of the domains below をオンにします。
- Select Domains で、SSO を必須にするドメインをオンにします。
- (任意)Specify users who can bypass SSO sign-in に、対象のユーザーを追加します。
- Save を選択します。