Skip to main content
Hi. Could someone please assist?

I currently have ADFS setup for SSO for salesforce. the config in Salesforce is Assertion contains the Federation ID from the User object. I would like to change this to Assertion contains the User's Salesforce username instead. however when I change this SSO no longer works. Do I need to change the way the Relaying Party Trust is setup for the Claims Issuance? I am unable to find any events in the eventlog. I feel as though I Am missign something simple but just can't quite put my finger on it. 

When I run the SAML Validation the error is Unable to map the subject to a Salesforce user. 

Any help would be appreciated.

Thanks

Neil.
2 respostas
  1. 30 de nov. de 2020, 10:32
    HI Neil,

    Can you check what is the value set as unique identifier in ADFS? 

    For example: Incase you have mapped Email , then if there is an exact match for email in Federation Id field of salesforce,  SSO would work. Now if you are changing from Federation Id to username, you need to ensure that the value matches with ADFS unique identifier value. 

    (Simple approach, 1) If all these days SSO setup Federation Id is working, just check if the value of Federation Id matches with that user's username. If it is different, change it to match with Fed Id.

    2) In the SAML assertion validator what is the value coming in the error message? Check if this is same as of your username? 

    Hope this helps you. Please mark this answer as best so that others facing the same issue will find this information useful. Thank you
0/9000