Skip to main content

#SingleSignOn0 debatiendo

Hi all ,

I have searched the internet high and low regarding this issue but found no help. So I am posing the question and hopefully there are some answers to this. I am working on enabling single sign-on with my university's Identity Provider.  

I am using eduPersonPrincipalName as Attribute Name and urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified as Name ID Format.

The login passed on the Identity Provider side but when they redirected it to my salesforce domain, the SSO error page shows up, saying "We can't log you in because of an issue with single sign-on. Contact your Salesforce admin for help." I don't get why Salesforce isn't accepting my IdP logins.  I am asking if there are other places I need to configure? Yes, I have checked SAML Enabled and Federation ID aren't the issue here since I am using Username for SAML Identity Type. My IdP told me that they are not seeing any errors on their side and the attributes passed perfectly. So how do I configure my salesforce single sign-on settings to allow my IdP to pass through the login process? 

 

The SAML response shows that all the check-ins are "OK" but still unable to map the subject to a salesforce user, that's strange. 

 

#Security #SAML Single Sign On #SingleSignOn #Authentication #Integration 

 

Single Sign On Error- using eduPersonPrincipalName as attribute name

8 respuestas
0/9000

I'm encountering an error where I do everything that I'm told to do under "Set Up Single Sign-On for Your Internal Users

 

After completing everything that I'm told to do up until step 2, the login URL under endpoints don't look similar to the example. It does not include{ so=(numbers and letters) } after the domain URL. 

 

As a result, I am unable to complete this part of the lesson. 

 

Can I get some help? 

 

#SingleSignOn  #SAML Single Sign On  #SAML SSO

10 respuestas
0/9000

Check how we can set up Single Sign-On between two Salesforce org. No need to remember passwords for multiple orgs, using SSO setup one org and connect another org with it.

 

#SingleSignOn #SAML Single Sign On #SSO  #SF2SF Salesforce To Salesforce #Salesforce SSO  

2 comentarios
0/9000

For folks who are well versed with setting up SSO - As you are aware that it is a lengthy process to set up 1 User, wanted to undertsand if the manual process for setting up bulk Users, say 100 Users can be done with any automation tool?

 

Setting up 1 user takes precisely around 15-20 mins (Given it is your first time), would like to get in touch with someone who has set up SSO for bulk users.

You may please answer in the comments section below, or message if you are not comfortable posting publicly or you can write to me at neetusushma@gmail.com or DM on Twitter handle @neetusushma .

Any inputs highly appreciated. #SSO #SAML SSO #Salesforce SSO #Sales Cloud #SingleSignOn

0/9000

Hello all, I am trying to embed a web application into Salesforce using an iFrame. I have set up single sign on into the application using Salesforce as an Identity Provider, but after embedding it into an iFrame I keep getting "Login Failed: Unable to find a valid CSRF token. Please try again." Is there a way to bypass this, or another way to fix this at least and display an external application within Salesforce? Any help would be greatly appreciated 

 

#Lightning Web Components  #SingleSignOn  #Connected Apps Help  #Service Cloud  #Automation  #Integration

1 respuesta
0/9000
1 respuesta
  1. 26 jul 2021, 17:05
    1. Select Setup > Administration Setup > Manage Users > Profiles.
    2. Beside the desired profile, select Edit.
    3. Scroll down to General User Permissions, and check the Is Single Sign-on Enabled permission check box.
    4. Save the user profile.

    Mark this as best if helps

0/9000

We are looking to enable MFA and we are also currently using SSO with our System Admins having User Names/Passwords to get in if SSO goes down.  If we enable the 'Disable Login with Salesforce Credentials' feature in Salesforce how will System Admins log into the system?

 

I have turned this on and I'm unable to login without SSO.  I've heard in a Support Case that I can append something to the end of my Domains URL but that didn't work.  I've also read into Delegated Authentication but I find it strange we have to set a separate Web Service for this and that Salesforce doesn't just have an exclusion list like many others do.

 

Any help would be appreciated, thank you!

 

#Sales Cloud #SSO Identity Provider #SingleSignOn #Salesforce Admin

2 respuestas
  1. 12 jul 2021, 10:04

    Thanks Frank,

     

    I'm not sure I'm clear on what occurs after adding that to the end of the URL for login.  I've tested this and even with adding that to the end of the URL I still only have the option to login via our SSO through Google or with a User Name/Password but doing that it gives me an error message:

     

    Please check your username and password. If you still can't log in, contact your Salesforce administrator.

     

    I'm not able to login outside of SSO as a System Admin with my credentials when I've set my system up to 'Disable Login with Salesforce Credentials' so still unclear on how this can be configured.

     

    Thanks, John

0/9000

The documentation about how to set up SSO for an individual SF profile is out of date. It tells me to go to administrative permissions, which isn't a section that appears for me on the profile settings. I looked everywhere I could think of to try to find the setting to allow SSO for a specific profile. 

 

I am an sys admin and have SSO enabled for myself, so I know that SSO is set up for our instance and that I have the right level of permissions. 

 

#SingleSignOn

3 respuestas
0/9000

Hi,

 

We have Single sign-on(SSO) for internal and some external users, we also have some users in MC and Social Studio that don’t use SSO Is it possible to have both SSO using Azure and enable MFA for the non-SSO users?

 

We have an option to select with users to enable SSO on a user level but I could see this option in the presentation. Would this affect the SSO solution that we have or would it just use SSO for the enable users and for the disabled users it will just use the MFA?

 

Do we have any test environment where we can test this?

2 comentarios
  1. 14 ago 2020, 15:24
    In accounts using Single Sign-On (SSO), multi-factor authentication (MFA) is not enforced for users that are enabled to log in using SSO. We recommend that customers enable MFA functionality in their identity provider for these users. Users in the account that are not enabled for SSO, such as a Marketing Cloud admin backup, still use MFA to log into Marketing Cloud. Please refer to documentation and FAQ for MC MFA at https://help.salesforce.com/articleView?id=mc_overview_mfa.htm&type=5
0/9000

After integration of our Identity Provider for SSO, a Marketing Cloud SP Initiated Link was made available.

 

Using this link, the single sign on works technically fine... but is there any more convenient way to use SSO instead of giving business users this long and cryptic link?

 

How is the normal login-flow intended in SFMC standard with SSO? Is it only intended to have a login coming from a third party location (like the IDP) and not using a (short and usable) Login-URL from SFMC?

2 comentarios
  1. 12 jun 2020, 15:46
    Hey @Christopher Hanna

    - I wondered the same thing recently and was told that the "long and cryptic link" was basically necessary because once you setup SSO, you have to login to SFMC with the IDP link.

    It's slightly different when logging into the Salescloud instance when you setup the My Domain function, but that doesn't exist for Marketing Cloud (to my knowledge). So, in our organization, we just setup buttons on our Intranet to use that long url and told people to just setup personal browser shortcuts or favorites using that link. After the first day, people got used to it. I suppose you could use a link shortener, too, if you really wanted to.

0/9000