Skip to main content

#SSO Setup0 personne en discute

In salesforce I deactivating the users who are not using their salesforce account for some time period(Ex 15 days). but whenever the deactivated user wants to login to their salesforce account it should allow the user to login without any issues. To login we are using SSO and direct Username and password method as well. So in SSO settings we are having the  SAML Identity Type as UserName not FederationId. When I tried to use the SAMLJITHandler method is not allowing me to save and showing the error federation Id. So is it possible to achieve my requirement without using the FederationId If yes Please guide me or else what are all the steps I need to follow? currently we are using UserName as the SAML Identity Type Thanks in advance.

 

#Salesforce Developer  #SSO Setup  #SSO Configuration  #SSO Error  #Saleforce Administrator  #Trailhead Support

1 réponse
0/9000

Hi not sure if anyone can help. I've setup OpenID Connect Auth. provider for Microsoft Azure Active Directory. Via the Test URL on the Auth. provider, I am being redirected to MS login page. Once I enter my credentials and redirects to Salesforce, I get this error 

 

OpenID Connect SSo Integration with Microsoft Azure AD

 

#SSO Setup  #Salesforce

2 réponses
0/9000
Dilipan M (Equiniti) a posé une question dans #SSO

My single sign on shows two different expiration date.

When I checked the SAML Single Sign On settings page in setup, for the field 'Identity Provider Certificate', It shows the following value 'CN=Microsoft Azure Federated SSO Certificate

Expiration: 4 Jul 2026 13:10:37 GMT'

 

I then opened the certificate itself, present on the field Request Signing Certificate, it says that the expiration date is in 2024.

 

Which is the true expiration date?

 

I checked with my Identity Provider team, they said it is 2026, but want to double check why it is showing 2024 in SF.

 

#SSO  #SSO Setup  #Single Sing-on  #Security  #Identity & Access Management

1 réponse
  1. Forum Ambassador Sushil Kumar (UKG)
    21 févr. 2024, 11:23
    Those are two different types of certificate. Request signing certificate could be used by your IDP to verify the Auth N request coming from Service provider (which is Salesforce in this case). A lot of cases IDP may not verify this certificate. You can check with your IDP team if they use SF request signing certificate for auth N request(For SP initiated SSO). The second certificate is the IDP certificate which is provided by your IDP, when IDP posts SAML response, they sign response with that certificate, and then Salesforce can use certificate uploaded in SF to verify the response to make sure it’s coming from right source.
0/9000
Jim Clarke a publié du contenu dans * Marketing Cloud Engagement *

Good Morning,

I wanted to confirm a documentation point for SSO setup with Salesforce; reading the documentation here:

https://developer.salesforce.com/page/Configuring-SAML-SSO-to-ExactTarget

In the first set of MC steps there appears to be an option to select SAML

 

In all of my accounts, the key management feature is there but the check box SAML is not an option (see attached).

 

Is SAML provisioned separately from the others, I would have thought Key Management was all options but wasn't 100% sure.

 

Thanks for any insight.

4 commentaires
  1. 11 oct. 2016, 15:45
    Hello @Jim Clarke

    I believe you will need to reach out to your account executive to get this process started as it is a separate SKU.

    Thanks!

0/9000

We have SAML enabled SSO setup and have the IDP certificate uploaded to Salesforce. The Request Signature Method is 'RSA-SHA1'. I guess this should not be impacted by this change. Can someone please clarify.

Thanks.

2 commentaires
0/9000