You are here:
Considerations for Creating Experience Cloud Site Users
All users who log into an Experience Cloud site must have a record in Salesforce. Their record is created either as a person account or as a contact connected to a customer or partner business account. External users are enabled from the contact record as a customer or partner user, depending on your business relationship.
Required Editions
| Available in: Salesforce Classic and Lightning Experience |
| Available in: Enterprise, Performance, Unlimited, and Developer Editions |
| Applies to: LWR, Aura, and Visualforce sites |
- All Experience Cloud site users who log in to a site must have an assigned Experience Cloud user license . View your available user licenses in Setup | Company Settings | Company Information.
- When creating any external user, the account that the new contact is associated with must have an account owner that is assigned a role in Salesforce.
- The Log in to Experience as User action is available from the actions list on the contact record in Lightning Experience. In Salesforce Classic, click Manage External User to access the Log in to Experience as User button.
- You can only configure the Log in to Experience as User action on the contact layout in Lightning Experience. After you enable a partner or customer user in Salesforce Classic, Log in to Experience as User is available on the contact record, even if it’s been removed from the contact layout.
- To troubleshoot issues or ensure that the site is configured appropriately, on the contact detail page, select Log in to Experience as User. Unless you have a higher role than the partner or customer user that you’re logging in as, you must have Edit permission on Accounts to log in as a partner or customer user. A new browser window opens, and you’re logged in to the community on behalf of the external user.
- When you log in as an external user, you see the behavior that the external user sees. For instance, external users see only the site dropdown menu if they have access to more than one active site. If external users have access to only one active site and they view another site in preview, the users don’t see the dropdown menu in the preview site.
- When logged in as another user, an admin or support user can’t authorize OAuth data access
for the user. For example, if an admin logs in as another user, the admin can’t authorize OAuth
access for third-party applications to user accounts. This restriction includes single sign-on.
- When multi-factor authentication (MFA) is enabled for a site, admins can’t use the login to access the site. See Implement Multi-Factor Authentication.
- Users and administrators can only log in to sites that they’re members of. To allow a user to log in using Experience Cloud sites, make internal and external users members of the site. If they aren’t a member, and attempt to log in, they see a site membership error.
- Create a user profile to assign to your external users. By default, Salesforce prevents you from creatingExperience Site users with standard profiles. Assign user licenses using profiles.
- Customer or partner users can’t directly log in to Salesforce. They must use an Experience Cloud site to access your Salesforce data. To add a customer or partner user,add their user profiles as a member of an Experience Cloud site.
- Customer Users don’t see the Notes & Attachments related list on accounts or contacts. Site users can’t own accounts enabled for sites.
- As it is with internal users, external users can’t be deleted. If you no longer want an external user to have access to a site, deactivate the user.
- When you search in your Salesforce org for site user records, sometimes finding them can be difficult. The reason is when you create a site user through Create External User from a contact record, the new user record is assigned to a site’s unique network ID. Global search looks for records in the internal org, which has a different network ID than the site. A global search doesn’t search inside sites. Because the user record is associated with a site network ID, global search doesn’t return results for that record. The workaround is to create user records in the internal org, and then associate the records to a site. You can associate an internal User record to a community by linking the internal record to a contact record. After you create the link, you can find the user record through global search. The user record’s network ID is now associated with the internal org.
- Users with the Delegated External User Administrator profile and Manage External Users or Manage Customer User permissions can’t select profiles for new users unless the profiles are added to the Assignable Profiles list. These profiles are added when setting up the delegated external administrator. For more information, see Delegate Site Administration to an External User.
Check out this quick video about how Experience Cloud sites live in an org, the differences between Experience Cloud licenses, and how Salesforce accounts and site users are associated with one another.
Did this article solve your issue?
Let us know so we can improve!
