Staff login to Salesforce via our "my.salesforce.com" domain. This URL uses SSO from our local ADFS server that authenticates all company applications.
Customers + Staff have access to a Salesforce Community. Customers directly login, and staff can use the "Employee Login" link under the login form, which redirects them to our local SSO page for SSO login.
If staff login to internal Salesforce, and then browse to our community URL after by going to community.ourcompany.com, it doesn't carry over their internal authentication. They have to click the "staff login" link and SSO into the community.
Is there a way we can have it that if a staff member has SSO'd into internal Salesforce, but later surfs to the customer community, that it can see they've already logged in and simply drop them into the authenticated community without the need to login yet again?
7 answers
As a result of me pushing a related idea, I have been directed by an internal Salesforce architect to how the internal Salesforce vs. experience cloud login was originally designed to accommodate switching between the two experiences (and why it's not a seamless 1:1 login between the two OOB).
Please see the following reference:
https://help.salesforce.com/s/articleView?id=sf.networks_navigate.htm&type=5