Salesforce supports a SAML-based single sign-on (SSO) service for its web-based
application that you can configure in your RapidIdentity portal. These
configuration settings are an example and may vary for individual
configurations.
Salesforce supports both SP-initiated SAML and IdP-initiated SAML:
- Use SP-initiated SSO when all users authenticate to the same Salesforce
URL.
- Use IdP-initiated SSO when users need to authenticate to different Salesforce
Communities and applications.
Requirements
- Salesforce administrator credentials
- Access to your RapidIdentity administrator portal
- In Salesforce, navigate to and click New.
- Configure the following SAML single sign-on settings:
| Setting | Value |
|---|
| Name | RapidIdentity_IDP |
| Identity Provider Certificate | Upload the certificate from . |
| SAML Identity Type | Assertion Contains the User's Salesforce Username |
| SAML Identity Location | Identity is in the NameIdentifier element of the Subject
Statement |
| Service Provider Initiated | HTTP Redirect |
| Identity Provider Login URL | https://RapidIdentityEntityID/profile/SAML2/Redirect/SSO |
- Click Download Metadata to retrieve the metadata
file.
- Navigate to your RapidIdentity administrator portal.
- From the module selector, choose Configuration.
- Select .
- Click , then click Create SAML Relying Party.
- In the General section, set the following:
- Name: Salesforce
- Description: SAML SSO Configuration for Salesforce
- Metadata: Paste the metadata downloaded from Salesforce.
- Click Save.
RapidIdentity and Salesforce are now integrated, allowing users to authenticate to
Salesforce with their RapidIdentity credentials.