Suggested answer

SAML SSO (Security Assertion Markup Language) allows users to authenticate with an Identity Provider (IdP) and access Salesforce without re-entering credentials.

Configuration steps:

1. In Salesforce, navigate to Single Sign-On Settings and enable SAML.
2. Create an SSO configuration with the IdP's Issuer URL, IdP certificate (uploaded to Salesforce), and the Login URL.
3. The IdP is configured with Salesforce's Audience URL (Entity ID) and ACS (Assertion Consumer Service) URL.

Key SAML Assertion components:
- Issuer: The IdP's unique identifier.
- Subject (NameID): The user identifier (Salesforce username or Federation ID).
- Audience: Must match Salesforce's Entity ID.
- Conditions: Time bounds (NotBefore, NotOnOrAfter) to prevent replay attacks.
- Signature: The IdP digitally signs the assertion using its private key; Salesforce verifies using the uploaded certificate.
- Relay State: Optional parameter that tells Salesforce where to redirect the user after successful authentication (deep link).

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.