These steps will guide you through setting up the single sign-on functionality between ADSelfService Plus and SalesForce.
Login to ADSelfService Plus as an administrator.
Navigate to Configuration → Self-service → Password Sync/Single Sign-on.
Locate and click on SalesForce in the list of applications provided.
Click on the Download SSO Certificate link in the top-right corner of the screen.
In the pop-up that appears, copy the Login URL, Logout URL and download the SSO certificate by clicking on the Download SSO Certificate button.
SalesForce (Service Provider) configuration steps
Log in to Salesforce with administrator credentials.
Select Setup Single Sign-On (SSO) option from the Security Controls tab.
Enter a Name and API Name for reference.
In the field Issuer, enter the Login URL copied in the Step 5 of Prerequisite
Upload the verification certificate in the field Identity Provider Certificate downloaded in the Step 5 of Prerequisite
In the Identity Provider Login URL field, enter the Login URL copied in the Step 5 of Prerequisite
In the Identity Provider Logout URL, enter the Logout URL copied in the Step 5 of Prerequisite
for redirecting users to when they sign out.Save the configuration
Copy the Login URL which is your SAML Redirect URL in ADSelfService plus configuration.
To map SSO Login to login page:
Navigate to Domain Management → Domain
Edit domain settings.
Enable SSO Configuration and Choose Login Method.
Add the domain created or registered domain.
Eg: https://purebmc.my.salesforce.cpm
ADSelfService Plus (Identity Provider) configuration steps
Now, switch to ADSelfService Plus’ SalesForce configuration page.
In the Domain Name field, enter the domain name of your email address. For example, if you use johndoe@thinktodaytech.com to log in to SalesForce Online, then thinktodaytech.com is the domain name.
Enter the SAML Redirect URL field with Login URL you had saved in Step 9 of SalesForce configuration.
Enter a Description for the connection.
In the Available Policies field, select the policies for which you wish to enable single sign-on.
Click Save.
Your users should now be able to sign in to SalesForce Online through ADSelfService Plus.
For SalesForce, Both IDP-initiated flow and SP-Initiated flow is supported. |