Configuring SAML-Based SSO with Salesforce

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Salesforce supports a SAML-based single sign-on (SSO) service for its web-based application that you can configure in your RapidIdentity portal. These configuration settings are an example and may vary for individual configurations.

Salesforce supports both SP-initiated SAML and IdP-initiated SAML:

  • Use SP-initiated SSO when all users authenticate to the same Salesforce URL.
  • Use IdP-initiated SSO when users need to authenticate to different Salesforce Communities and applications.
Requirements
  • Salesforce administrator credentials
  • Access to your RapidIdentity administrator portal
  1. In Salesforce, navigate to Setup > Single Sign-On Settings and click New.
  2. Configure the following SAML single sign-on settings:
    SettingValue
    NameRapidIdentity_IDP
    Identity Provider CertificateUpload the certificate from RapidIdentity Configuration > Identity Providers > IDP Configuration.
    SAML Identity TypeAssertion Contains the User's Salesforce Username
    SAML Identity LocationIdentity is in the NameIdentifier element of the Subject Statement
    Service Provider InitiatedHTTP Redirect
    Identity Provider Login URLhttps://RapidIdentityEntityID/profile/SAML2/Redirect/SSO
  3. Click Download Metadata to retrieve the metadata file.
  4. Navigate to your RapidIdentity administrator portal.
  5. From the module selector, choose Configuration.
  6. Select Security > Identity Providers > Federation Partners.
  7. Click Add Federation Partner > SAML 2.0, then click Create SAML Relying Party.
  8. In the General section, set the following:
    1. Name: Salesforce
    2. Description: SAML SSO Configuration for Salesforce
    3. Metadata: Paste the metadata downloaded from Salesforce.
  9. Click Save.

RapidIdentity and Salesforce are now integrated, allowing users to authenticate to Salesforce with their RapidIdentity credentials.