Configuring OpenID SSO for Freshservice

These steps show you how to configure the single sign-on (SSO) functionality using OpenID between ManageEngine ADSelfService Plus and Freshservice.

  • Do not terminate the session before the configuration is complete in both the identity provider and the service provider.
  • Please ensure that HTTPS is enabled in ADSelfService Plus.
  1. Login to ADSelfService Plus as administrator.
  2. Go to Configuration > Password Sync/ Single Sign On then click Add Application. Select Freshservice from the list.
  3. Note: You can also use the search bar at the top-left of the page to search for the application.
  4. Click IdP Details and select the SSO(OAuth/OpenID Connect) tab.
  5. Note the Client ID, Client Secret, Issuer, Authorization Endpoint URL, Token Endpoint URL, and User Endpoint URL values.
  6. IdP details for Freshservice in ADSelfService Plus
  1. Login to Freshservice with admin credentials.
  2. Go to Admin > General Settings > Security Settings.
  3. Select Helpdesk Security.
  4. SP details for Freshservice in ADSelfService Plus
  5. Click the Modify Login Policy button in the Default Login Policy tab.
  6. Modifying the Freshworks login policy for SSO in ADSelfService Plus
  7. Toggle the status of Single Sign-on to enabled.
  8. Enabling SSO for Freshworks in ADSelfService Plus
  9. You can select OAuth 2.0 or OIDC under IdP of your choice. It is recommended to choose OIDC.
  10. Configuring SSO for Freshworks in ADSelfService Plus
  11. If you have chosen OIDC, fill the following fields under Map information from IdP with the corresponding details saved during Step 4 of the Prerequisites:
    1. Client id: Client ID
    2. Client secret: Client Secret
    3. Enter the Scopes to specify the level of access of the access tokens. It is necessary to include the openid scope in this field.
    4. Authorization URL: Authorization Endpoint URL
    5. Access token URL: Token Endpoint URL
    Setting up SSO for Freshworks in ADSelfService Plus
  12. If you have chosen OAuth 2.0, you will have to fill all the details in the previous step, plus the User info URL field with the User Endpoint URL information saved in Step 4 of the Prerequisites.
  13. OAuth SSO for Freshworks in ADSelfService Plus
  14. Copy the Redirect URL under Map information in IdP for later steps.
  15. Mapping IdP information for Freshservice in ADSelfService Plus
  • Click Configure SSO.
    1. Switch back to ADSelfService Plus' Freshservice configuration page.
    2. Configuring SSO information for Freshdesk in ADSelfService Plus
    3. Enter the Application Name and Description as per your preferences.
    4. Enter the Domain Name of your Freshservice account. For example, if your Freshservice username is johnwatts@thinktodaytech.com, then thinktodaytech.com is your domain name.
    5. In the Assign Policies field, select the policies for which SSO need to be enabled.
    6. Note: ADSelfService Plus allows you to create OU and group-based policies for your AD domains. To create a policy, go to Configuration > Self-Service > Policy Configuration > Add New Policy.
    7. Under the SSO tab, select Enable Single Sign-On.
    8. Choose OAuth/OpenID Connect from the Select Method drop-down.
    9. Enter the Freshservice portal's login URL in the SP Login Initiate URL field.
    10. Note: Freshservice requires sign-in to begin from their login page, known as SP-initiated login. Users are first directed to the Freshservice login page, specified in the SP Login Initiate URL field, after which Freshservice (the SP) redirects them to ADSelfService Plus (the IdP) for authentication.
    11. Enter the Redirect URL copied in Step 9 of configuring Freshservice in the SSO Redirect URL field.
    12. Using the Scopes drop-down, select openid, which is the scope required for OIDC authentication. You can also specify scopes such as profile or email to include extra user information in the authorization request.
    13. Note: Scopes specify the level of access the access token has. They are typically included in the authorization request. Specify the scopes for which you wish to allow access to your authorization token, using the drop-down.
    14. Click Add Application to save the configuration.

    The Well-known Configuration URL in the IdP details pop-up contains all the endpoint values, supported scopes, response modes, client authentication modes, and client details. This is enabled only after you finish configuring the application for SSO in ADSelfService Plus. You can provide this to your service provider if required.

    Go to Top

    Your request has been submitted to the ADSelfService Plus technical support team. Our technical support people will assist you at the earliest.

     

    Need technical assistance?

    • Enter your email ID
    • Talk to experts
    •  
       
    •  
    • By clicking 'Talk to experts' you agree to processing of personal data according to the Privacy Policy.

    Don't see what you're looking for?

    •  

      Visit our community

      Post your questions in the forum.

       
    •  

      Request additional resources

      Send us your requirements.

       
    •  

      Need implementation assistance?

      Try OnboardPro

       

    On this page

    Copyright © 2025, ZOHO Corp. All Rights Reserved.