Loading
Salesforce now sends email only from verified domains. Read More
Identify Your Users and Manage Access
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Map Salesforce Users to the SAML Service Provider

          Map Salesforce Users to the SAML Service Provider

          To ensure that your SAML service provider can recognize Salesforce users when they log in with single sign-on (SSO), update user information in Salesforce. Provide user identifiers that the service provider recognizes.

          Required Editions

          Available in: both Salesforce Classic and Lightning Experience
          Available in: Developer, Enterprise, Performance, Unlimited, and Database.com Editions
          User Permissions Needed
          Define and modify identity providers and service providers: Customize Application

          Before you start, complete these steps.

          The identifier you use depends on which Subject Type the service provider expects in the SAML assertion. For example, if the Subject Type is Username, the service provider expects the user’s Salesforce username in the subject of the SAML assertion. Salesforce sends the username in the SAML assertion, and the service provider recognizes it and identifies the user. You specify the Subject Type when you integrate the service provider as a SAML-enabled app.

          If the Subject Type is Federation ID, you must provide a Federation ID in the user’s Salesforce settings. By updating the Federation ID, you ensure that the service provider can recognize the user when Salesforce sends SAML assertions.

          To map multiple users at a time, use SOAP API. For more information, see SOAP API Developer Guide

          To map an individual user in your org to the service provider, complete these steps.

          1. From Setup, enter Users in the Quick Find box, then select Users.
          2. Find the user and click Edit next to their name.
          3. Under Single Sign On Information, for Federation ID, enter an identifier that the service provider can recognize. For example, enter the username to be used to log into the service provider.
          4. Save your changes.
           
          Loading
          Salesforce Help | Article