Skip to main content
Lam Aik Pea ha fatto una domanda in #Data Management
Hi,

 

I would like to implement SSO in my SFDC org, most probably using SAML. I am wondering if i were to implement SSO, how would Connect for Outlook client supports SSO since these client needs to login using both password and security token?

 

Appreciate some feedback. Thanks.
1 risposta
  1. 22 set, 10:35

    Hi Lam,

    When you implement Single Sign-On (SSO) using SAML, desktop clients like Connect for Outlook handle authentication through your identity provider (IdP) rather than requiring standard Salesforce passwords and security tokens.

    Here is how the authentication flow works and how it bypasses the traditional password-plus-token requirement: 

     

    1.Configuring the Connection URL:Custom Domain & Redirect. 

    When setting up Connect for Outlook in an SSO-enabled environment, users configure the plugin to point to your organization's custom My Domain URL rather than

    login.salesforce.com

    . When the client attempts to connect, Salesforce recognizes the host domain and redirects the authentication request directly to your Identity Provider (such as ADFS, Okta, or Azure AD). 

     

    2.Handling Authentication Securely:Token Assertion. 

    Instead of passing a plaintext username and password, the client uses an OAuth or browser-based flow where the user authenticates against your corporate IdP. Once verified, the IdP sends a cryptographically signed SAML assertion back to Salesforce over SSL. Salesforce validates this token and issues a session ID back to the Outlook plugin, completely removing the need for a security token or standard password.

0/9000