Loading

How to Configure SAML When IdP Requires Tableau Entity ID and ACS URL

Дата публикации: Jul 15, 2026
Предварительные требования
Site Administrator access to Tableau Cloud, administrative access to the external Identity Provider (IdP) configuration portal, IdP that requires Tableau Cloud Entity ID and ACS URL before saving SAML configuration
Задача

In Tableau Cloud, you can register multiple IdPs to a single site. Consequently, Tableau Cloud dynamically generates the unique, correct Entity ID and ACS URL for an IdP only after that IdP's metadata has been uploaded. This design creates a circular dependency if the external IdP strictly requires Tableau Cloud's metadata to initiate or save its own application setup.

To resolve the circular dependency between Tableau Cloud and the IdP, exchange the Entity ID and ACS URL using temporary values to establish SAML SSO.

Действия
  1. In your IdP's SAML configuration screen, enter temporary URLs to save the settings and download the IdP metadata (XML file).
    For example, enter the following:
    1. Temporary Entity ID: 
      https://sso.online.tableau.com/public/sp/metadata?alias=12345
    2. Temporary ACS URL: 
      https://sso.online.tableau.com/public/sp/
  2. Navigate to the "2. Upload metadata to Tableau" section on the Tableau Cloud configuration screen, upload the IdP metadata file obtained in Step 1, and click Save and Continue.
  3. Once the screen proceeds to the "5. Get Tableau Metadata" section, copy the dynamically generated, correct Tableau Cloud Entity ID and Tableau Cloud ACS URL.
    Note: If you plan to use Single Logout or encrypted certificates, download the XML file via Export Metadata on the same screen.
  4. Return to your IdP's configuration screen, and overwrite the temporary URLs entered in Step 1 with the correct information obtained in Step 3, then save.
Дополнительные ресурсы

For more information, see SAML in Tableau Help.

Номер статьи базы знаний

005388937

 
Загрузка
Salesforce Help | Article