Superbadge を獲得すると、学習したスキルを複雑な現実世界のビジネス上の問題に適用して活用することができます。これらの評価には、より高いレベルのスキルと知識が求められます。手順どおりに進める Challenge とは異なり、完了までにより多くの時間がかかることもよくあります。
Configure and Test SAML SSO Settings
Next, configure inbound SSO. In this step, you’ll use the Axiom Heroku web app as the identity provider (IdP). Axiom has provided you with the following Security Assertion Markup Language (SAML) settings for the Salesforce configuration.
Field | Value |
|---|---|
Name | Axiom SSO Test |
API Name | Axiom_SSO_Test |
Issuer | https://axiomsso.herokuapp.com |
Identity Provider Certificate | Download the Identity Provider Certificate from Axiom, then upload in this field. |
Request Signature Method | RSA-SHA1 |
SAML Identity Type | Federation ID |
Identity Provider Login URL | https://axiomsso.herokuapp.com/RequestSamlResponse.action |
Entity ID | <The org’s My Domain URL> |
Now that you have SSO enabled and set up in the Salesforce org, test your configuration by generating a SAML response from the Axiom Heroku web app. Make sure the Murphy Jean user's email address is verified and set as yours to receive the verification code. A successful test allows you to log in to the org via SSO as the Murphy Jean user.
- The Axiom SAML version must match the version in your SAML SSO Settings.
- Set the Recipient URL to the Login URL endpoint.
Finally, make sure that users are unable to bypass the SSO requirement by preventing direct login from login.salesforce.com. And, since you always have user experience in mind, add a button to the org’s My Domain login page that takes users directly to the Axiom SSO Test authentication service.
As a seasoned Salesforce consultant, you’re well aware that MFA is required for all users. Cumulus Global Bank has decided that the MFA requirement will be completed through the SSO IdP, so it doesn’t need to be configured within Salesforce for SSO users.
