Single-Sign-On for Salesforce via SAML Assertions

Salesforce-specific notes on implementing and configuring single-sign-on via SAML

IdP Settings

SP Settings

SSO Configuration

JIT Provisioning

SSO for Communities

In order to set up SSO for Communities users, follow these steps:

  1. Set up a standard SAML configuration
  2. Modify the ACS URL (place where you send SAML messages) in your IDP to the following:
    1. COMMUNITY_URL/login?so=ORGANIZATION_ID
      • Note that this is your regular ACS URL with the Community URL + /login instead of your My Domain
  3. Optionally set up your Community for SP-Initiated SSO