Skip to main content

How to allow Admin users to bypass SSO to log in directly to Salesforce with a username and password

Hi, we have set up SSO/MFA on our Org, using Azure AD as our Identity provider. Doing this has removed the native Salesforce login for all users.  BUT we want to allow for Admin users to bypass SSO and have the option to log in directly to Salesforce with a username and password in case of a problem with SSO login and for other Admin tasks like Sandbox set up and maintenance.  Any help or tips on how to allow for this kind of setup?  Azure SSO works fine but when attempting to browse to the URL - http://login.salesforce.com/ we are not able to login with our usual SysAdmin username and password.    The suggested solution in MyDomain settings to "Keep 'Login Policy' unchecked "  seems to me to be an insecure workaround rather than a stable and secure solution for allowing the option of a separate local Salesforce login for our Admin users?    Do Salesforce have any official guidelines for a separate local logon in an enforced / compliant SSO-MFA environment?  Seems a major omission if not? 

11 answers
  1. Jan 15, 2022, 10:31 PM

    @Amnon Kruvi unless the “Is Single Sign-On Enabled" permission is given either at the profile level or via permission set, users can still choose between regular login and SSO on the login page (assuming both login forms are marked as available). In our case, we gave everyone the permission at the profile level except system admins, who will log in with credentials and the Authenticator app for MFA.

    Users who attempt to log in via credentials will just receive an error message, and since we use SSO they can't reset their passwords either. 

0/9000