Yandex Cloud
Search
Contact UsGet started
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • AI for business
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
© 2025 Direct Cursus Technology L.L.C.
Yandex Identity Hub
    • All tutorials
    • Differentiation of access permissions for user groups
    • Service account with an OS Login profile for VM management via Ansible
      • Overview
      • Managed Service for OpenSearch
      • Managed Service for GitLab
      • Zabbix
      • Yandex 360
      • SonarQube
  • Access management
  • Pricing policy
  • Terraform reference
  • Audit Trails events
  • Release notes

In this article:

  • Create an app
  • Set up the integration
  • Set up the SAML application in Yandex Identity Hub
  • Set up SAML authentication in Yandex 360
  • Add users
  • Make sure your application works correctly
  • Troubleshooting setup issues
  1. Tutorials
  2. Setting up single sign-on (SSO) for apps
  3. Yandex 360

Creating a SAML app in Yandex Identity Hub for integration with Yandex 360

Written by
Yandex Cloud
Updated at November 12, 2025
  • Create an app
  • Set up the integration
    • Set up the SAML application in Yandex Identity Hub
    • Set up SAML authentication in Yandex 360
    • Add users
  • Make sure your application works correctly
    • Troubleshooting setup issues

Note

This feature is at the Preview stage.

Yandex 360 is a cloud platform for business offering tools for setting up corporate email addresses, collaboration, and document management. Yandex 360 supports SAML authentication to provide secure SSO for your organization’s users.

To authenticate your organization's users to Yandex 360 via SAML SSO, create a SAML app in Identity Hub and configure it appropriately both in Identity Hub and Yandex 360.

SAML apps can be managed by users with the organization-manager.samlApplications.admin role or higher.

For the users of your organization to be able to access Yandex 360:

  1. Create an app.
  2. Set up the integration.
  3. Make sure the application works correctly.

Create an appCreate an app

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, select Apps.
  3. In the top-right corner, click Create application and in the window that opens:
    1. Select the SAML (Security Assertion Markup Language) single sign-on method.

    2. In the Name field, specify a name for your new app: yandex360.

    3. Optionally, in the Description field, enter a description for the new app.

    4. Optionally, add labels:

      1. Click Add label.
      2. Enter a label in key: value format.
      3. Press Enter.
    5. Click Create application.

Set up the integrationSet up the integration

To configure Yandex 360 integration with the SAML app you created in Identity Hub, complete the configuration both on the Identity Hub side and in Yandex 360.

Set up the SAML application in Yandex Identity HubSet up the SAML application in Yandex Identity Hub

Set up service provider endpointsSet up service provider endpoints

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, select Apps and then, the SAML app.
  3. At the top right, click Edit and in the window that opens:
    1. In the **SP EntityID ** field, specify https://yandex.ru/.
    2. In the ACS URL field, enter this address: https://passport.yandex.ru/auth/sso/commit.
    3. Click Save.

Configure user attributesConfigure user attributes

Warning

For integration with Yandex 360, set the User.EmailAddress, User.Firstname, and User.Surname attributes.

Set user attributes for integration with Yandex 360:

Cloud Center UI
  1. Log in to Yandex Identity Hub.

  2. In the left-hand panel, select Apps and select the desired app.

  3. Navigate to the Attributes tab.

  4. Edit user attributes:

    1. Replace the emailaddress attribute with User.EmailAddress. Proceed as follows:

      1. Click the row with the emailaddress attribute.
      2. In the Attribute name field, enter User.EmailAddress.
      3. In the Value field, leave SubjectClaims.email.
      4. Click Save.
    2. Replace the givenname attribute with User.Firstname.

    3. Replace the surname attribute with User.Surname.

    4. You can delete the fullname attribute as you will no longer need it.

For more information about configuring attributes, see Configure user and group attributes.

Collect data for setting up Yandex 360Collect data for setting up Yandex 360

To set up SSO in Yandex 360, you need the following data from your SAML app:

Cloud Center UI
  1. Log in to Yandex Identity Hub.

  2. In the left-hand panel, select Apps and then, the SAML app.

  3. Under Identity provider (IdP) configuration on the Overview tab, copy the following data:

    • Issuer / IdP EntityID: IdP entity ID.
    • Login URL: Entry point URL address (Login URL).
  4. Under Application certificate, click Download certificate and save the token signing certificate in X.509 format to your device.

You will need this data to set up SSO in Yandex 360.

Set up SAML authentication in Yandex 360Set up SAML authentication in Yandex 360

Note

To set up SAML authentication in Yandex 360, the user needs the organization administrator permissions.

To set up SAML authentication in Yandex 360:

  1. Go to the Yandex 360 for Business console.
  2. Navigate to the SSO settings section.
  3. Provide the data you got in the previous step:
    • IdP Entity ID: IdP issuer.
    • Login URL: Entry point URL.
    • Upload the token signing certificate in X.509 format.
  4. Save the settings.

Warning

Make sure the domain from the User.EmailAddress attribute in the SAML response matches the main domain or one of the alias domains of your Yandex 360 organization.

Add usersAdd users

For your organization's users to be able to authenticate in Yandex 360 with Identity Hub's SAML app, you need to explicitly add these users and/or user groups to your SAML application.

Note

Users and groups added to a SAML application can be managed by a user with the organization-manager.samlApplications.userAdmin role or higher.

Add users to the application:

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, select Apps and select the required app.
  3. Navigate to the Users and groups tab.
  4. Click Add users.
  5. In the window that opens, select the required user or user group.
  6. Click Add.

Make sure your application works correctlyMake sure your application works correctly

To make sure both your SAML app and Yandex 360 integration work correctly, authenticate to Yandex 360 as one of the users you added to the app. Proceed as follows:

  1. In your browser, go to the Yandex 360 login page.
  2. If you were logged in to Yandex 360, log out.
  3. On the authentication page, select Single Sign-On (SSO).
  4. On the Yandex Cloud authentication page, enter your email address and user password. The user or group they belong to must be added to the application.
  5. Make sure you are logged in to Yandex 360.

Troubleshooting setup issuesTroubleshooting setup issues

If you have specified incorrect values when setting up the IdP, you will get the Failed to log in message and the following error code on an attempt to log in via SSO.

email.not_in_responseemail.not_in_response

Specify attribute names in User.Firstname, User.Surname, User.EmailAddress format. If you specify another format, e.g., Firstname, you will not be able to log in.

request_your_adminrequest_your_admin

This error occurs if the administrator of your organization’s user folder has restricted access to Yandex 360 for your account. For more details, contact your organization’s support team.

samlresponse.invalidsamlresponse.invalid

This error occurs if either the entry point URL, IdP issuer, or token signing certificate was specified incorrectly. You may also get this error within 14 days prior to the expiration of the token signing certificate or after it expires. Validate your SSO settings in Yandex 360.

unsupportable_domainunsupportable_domain

Make sure the domain from the User.EmailAddress email attribute in the SAML response matches the main domain or one of the alias domains of your Yandex 360 organization.

Was the article helpful?

Previous
Zabbix
Next
SonarQube
© 2025 Direct Cursus Technology L.L.C.