Integrate Salesforce with Identity as a Service

A Salesforce account is automatically configured for single logout (SLO) when it is set up for Identity as a Service authentication. When the user logs out of a Salesforce Cloud account that is set up for Identity as a Service authentication, the user is also logged out of Identity as a Service. When the user logs out of Identity as a Service, the user is not automatically logged out of Salesforce Cloud.

You can also encrypt the assertions of this application.

Note: Entrust recommends using a Federation ID for the User ID of your Salesforce account. Modify the Username at Administration > Users > Users in your Salesforce account. When adding Salesforce to Identity as a Service, define a User Attribute that maps to the user ID settings in your Salesforce configuration.

Note: The instructions for this procedure apply to Salesforce Cloud accounts with the Lightning Experience user interface. You can follow the procedures if you have a Salesforce account with the classic user interface, but some of the steps may vary.

To integrate Salesforce with Identity as a Service you must do the following:

Step 1: Create a custom user attribute for Salesforce

Step 2: Create a custom domain for Identity as a Service in Salesforce

Step 3: Export the signing certificate from IDaaS

Step 4: Modify Salesforce settings to support encryption

Step 5 Configure Salesforce for SSO

Step 6: Complete the based on whether you selected Username or Federation ID as the SAML Identity Type in Step 5: Configure Salesforce for SSO.

Click here for instructions if you selected Assertion contains the Federation ID from the User Object

Click here if you selected  Assertion contains the User's Salesforce username

Step 7: Add Salesforce to Identity as a Service

Step 8: Create a resource rule to protect access to Salesforce