Zoho Vault
Zoho Vault is a cloud-based and enterprise-grade password manager that securely stores, shares, and audits credentials. It integrates with corporate identity systems for SAML-based SSO into Vault and can also provide SAML-based SSO out to connected SaaS applications from the Vault portal.
Key Capabilities
-
Directory onboarding: Integrates with Active Directory or LDAP and supports domain verification for seamless user import and synchronization.
-
Provisioning via Zoho Directory: Leverages Zoho Directory’s SCIM-based provisioning to synchronize users and groups into Zoho services, with Vault consuming these identities.
-
MFA options: Offers built-in multi-factor authentication through Zoho OneAuth, along with support for common authenticator and OTP methods.
-
APIs for automation: Provides REST APIs and SDKs for creating, reading, updating, and deleting secrets, enabling automated credential and workflow management.
Limitations
-
SCIM directionality: SCIM provisioning operates through Zoho Directory (for inbound sync into Zoho apps); Vault-specific SCIM endpoints or outbound provisioning to third-party targets are not publicly documented.
-
Scope: Designed as a secure password and secrets manager rather than a full-fledged Identity Provider (IdP) or CIAM platform; external IdPs should be used for broader identity governance and access control.
-
SAML-to-app compatibility: SAML-based app launches rely on individual app metadata and configuration. Attribute mappings and logout behavior should be validated per integration.