Hello ,
You can first try to setup SP initiated SAML as this will be starting point for MFA .
Later you can set IDP initiated SAML . ( okta dashboard ) .
Check SP SAML in below doc :
https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-in-Salesforce.html
While using Okta mobile for Single sign on it only allows my users to log in to salesforce classic with no option to switch to lightning. Keeping my users in OKTA mobile for SSO and not having them use the Salesforce app, does anyone know how my users can log into lightning?
#Lightning #Mobile #SSO #SAML Single Sign On #Single Sign-On #Okta SSO #OKTA #Okta Login Issue #OKTA Service Provider #Sales Cloud
12 ene 2022, 8:01 @Giuliano Zoccoli I'm facing the same aforementioned issue for one of the users and as mentioned by you all the above permissions have been set but still the same issue.
Any suggestions that might help us.
I have set up SAML Single Sign-On with Okta. I can log in fine using the Identity Provider login url but when I try to log in using Okta on the login screen, I get a Insufficient Privileges error message. I am not sure where I have gone wrong. Any advise?
12 oct 2021, 14:50 @Jack Mahony I am not able to open your screenshots. Also, Salesforce is SP or IDP?
We have SSO and use Okta. Is the only option to verify on a mobile device? That's not practical as we don't require employees to have a mobile device on hand.
Does Salesforce support any desktop verification method? If not this is going to kill user adoption.
27 may 2021, 22:43 @Linda Thompson when you have SSO and your SSO-Provider supports MFA already, you are anyway "save" already.
"All users who log in to Salesforce products … through the user interface must use MFA. To ensure that MFA is enabled for all your Salesforce users, you can turn it on directly in your Salesforce products or use your SSO provider's MFA service.”
Source:
https://help.salesforce.com/articleView?id=000356005&type=1&mode=1
If we are using a third-party authentication software like Okta, do we still need to enable MFA through Salesforce?
9 mar 2021, 14:34 Thank you @Dylan Silver for that, they must have updated the FAQ pages.
@Tammy Rahn wouldn't that be cool to link that statement link this > https://help.salesforce.com/articleView?id=000352937&type=1&mode=1#mfa-third-party-solution ;-)
I hope this is the right group to ask in - We're finding a weird behaviour with Single Sign-on and the Redirect policy on My Domain. If we set the Redirect policy to "Redirected with a warning to the same page within the domain" we would expect the warning page only to show up when people use the login.salesforce.com url.
However, we're using OKTA, which is set up to use our custom domain and our users still see that warning. This is confusing, as these users are following all the rules and doing everything right, so we'd like them to get logged in immediately.
I've raised a case with OKTA, who've stated that they don't think they can control this behaviour:
"...When using Okta though, the referer is seen as the application URL, in this case it would be https:/domain.okta.com/app/salesforce/<appid>/sso/saml. That is not recognized as the domain so it prompts the warning.
That explains why it shows up when using Okta, but unfortunately, we don't knwo if there is anything that can be done in this situation as that is the way all of our apps function."
Is there any explanation as to why SSO via OKTA would trip up the login redirect policy?
19 ene 2016, 11:26 Sorry, found it - https://success.salesforce.com/issues_view?id=a1p30000000SyXwAAK