You are here:
Supported SSO Scenarios: Salesforce as the Service Provider Control (Relying Party)
Enables users to authenticate to Salesforce with an external enterprise identity provider (IdP), centralizing authentication and access controls.
Control Name
Single Sign-On for Salesforce Org Access (Salesforce as Service Provider)
Control Overview
Enables users to authenticate to Salesforce with an external enterprise IdP, centralizing authentication and access controls.
Description
Users log in to Salesforce using credentials managed by an external IdP such as Okta, Azure AD, Ping, or other SAML/OpenID Connect-compliant providers.
Recommended Configuration
Enforce SSO for all users with MFA enabled, minimum 12-character password standards, and conditional access policies where applicable.
Security Impact
Reduces credential theft, phishing success, and unauthorized access by eliminating reliance on local credentials.
Business Impact
Improves compliance alignment, reduces security incidents, and strengthens governance over workforce access.
Security Risk If Not Configured
Local authentication with weaker password policies increases the likelihood of account takeover, especially for privileged users.
Threat Scenarios
Credential stuffing, phishing-based account takeover, abuse of compromised admin credentials.
Estimated CVSS Score Range
Critical (9.0–10.0).
Risk Impact Considerations
Risk increases for orgs with many admins, API users, or access to sensitive business processes.
Higher Risk When
MFA is not enforced, direct logins are allowed, or users access Salesforce from unmanaged devices.
Low Risk When
SSO with MFA, IP restrictions, device trust, and session assurance policies are enforced.
Business and Integration Considerations
Requires coordination with IAM teams. Salesforce natively supports SAML and OpenID Connect integrations.
Security Health Review Guidance
Security Health Review identifies missing or weak SSO enforcement and prioritizes remediation for workforce and privileged access.
Who Is Impacted
Internal employees, administrators, developers, and workforce users accessing Salesforce directly.
