Skip to main content

#IdP Vs SP0 utenti parlano di questo argomento

I am looking at the documentation for IdP and SP initiated SAML and seem to come across conflicting information if the IdP-initiated SAML supports deep linking. From what I understand, myDomain is required for deep linking in both cases (though generally optional for IdP-initiated SAML) and the IdP must support the RelayState parameter, but then I see other posts saying that only SP-initiated SAML can support deep linking. So which one is correct?

#SAML Single Sign On #Deep Links #IdP Vs SP #Identity and Access Management

1 risposta
0/9000

Hello!

 

Does Salesforce still support idP-initiated SSO?

 

We currently use idP-intiated SSO for Salesforce with our current idP (Idaptive), but we will be migrating our idP to Microsoft Azure so it works seamlessly with our Office365 subscription.

 

When setting up Azure as the identity provider, the only documentation I've found is for SP-initiated context, and in testing that is the only way I've been able to get it to work. I can "mimic" idp-initiated SSO if I set the Azure login as the only login option.

 

Anything I'm missing?

 

Thanks

6 commenti
  1. 22 mag 2020, 16:26

    Thank you everyone for your help!

    I finally got it

    The built in Salesforce app in Azure requires both an ACS URL and a Sign in URL. When both are present, Salesforce will use SP-initiated login flow.

    I created a custom app in Azure, recreated the SAML trust with Salesforce, and set only the reply URL in Azure.

    It now authenticates in idP-initiated context.

0/9000

That SSO session was amazing - thanks so much to @Charly Deloitte Prinsloo  for taking us through it. Join us for an in-depth tour around SSO with SAML! We talk about federated authentication, IdP vs SP-initiated flows, SAML parameters and My Domain.

SSO & SAML Study Group - Oct 2018

1 commento
0/9000