27.7.5 Configuring the SAML Provider

  1. Click Settings > Identity > Single Sign-On Settings.

  2. Upload the Identity Provider Signing Certificate that you obtained in Step 7 of section 27.7.3.

  3. In Single Sign-On Settings, click New and specify the following details:

    1. Name: Advanced Authentication.

    2. API Name: AAF.

    3. Issuer: https://AdvancedAuthenticationServerAddress/osp/a/TOP/auth/saml2/metadata, where you must replace AdvancedAuthenticationServerAddress with the domain name or IP address of your Advanced Authentication server.

    4. Entity ID: https://CompanyName.my.salesforce.com/.

    5. Click Browse to open the Identity Provider certificate.

    6. SAML Identity Type: Select Assertion contains the Federation ID from the User object.

    7. SAML Identity Location: Select Identity is in an Attribute element.

    8. Attribute Name: upn.

    9. Service Provider Initiated Request Binding: Select HTTP Redirect.

    10. Identity Provider Login URL: https://AdvancedAuthenticationServerAddress/osp/a/TOP/auth/saml2/sso.

    11. Select User Provisioning Enabled.

    12. Click Save.

  4. Click Edit for Federated Single Sign-On Using SAML.

  5. Select SAML Enabled.

  6. Click Save.

  7. Click Settings > Users.

  8. Click Edit for the required Salesforce users by adding Federation ID for the user accounts. The Federation ID corresponds to userPrincipalName attribute in Active Directory. For example, pjones@company.com.

    NOTE:The name that you specify in Federation ID is case sensitive. The following error appears, if you ignore the case:

    We can't log you in. Check for an invalid assertion in the SAML Assertion Validator (available in Single-Sign On Settings) or check the login history for failed logins.

  9. Click your profile icon and click Switch to Salesforce Classic.

    This mode is required to tune the domain options.

  10. Click Setup Administrator > Domain Management > My Domain > Edit to access the Authentication Configuration screen.

  11. Select Login Page and osp options.

  12. Click Save.