Suggested answer

The question I actually answer is: where does the identity of record live, and who owns the login experience?

For employees, Salesforce is almost always the service provider. The enterprise already has an identity provider that authenticates people across dozens of applications; adding a second authority for one of them fragments the experience and creates a second place to reset a password.

Salesforce is the identity provider when it is where the population is defined and where the journey starts — commonly for partners and customers in an Experience Cloud site who need onward access to other systems, or when the App Launcher is being used as the front door to a set of third-party applications for a group of employees whose primary system really is Salesforce.

For consumer identity I ask the same question about a dedicated customer identity platform. If one already authenticates the consumer across several non-Salesforce channels, Salesforce should accept that identity and keep the contact and consent data. If Salesforce owns the login and the surrounding experience, Salesforce Identity for customers is a reasonable choice. What I will not do is put credentials in both and synchronise them.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.