Suggested answer

Marketing Cloud supports two SSO approaches:
1. Salesforce CRM SSO (MC Connect): When Marketing Cloud Connect is configured, users with matching Salesforce CRM user accounts can log into Marketing Cloud using their Salesforce credentials. This requires the user's Salesforce username to match their Marketing Cloud username. Users are provisioned and linked in Marketing Cloud Setup under Users > Salesforce Users.
2. SAML-based SSO (External Identity Provider): Marketing Cloud can be configured as a SAML Service Provider. An external IdP (Okta, Azure AD, Ping Identity) authenticates the user and passes a SAML assertion to Marketing Cloud. Configuration requires:
— SAML metadata exchange between the IdP and MC
— Username/attribute mapping in the MC SSO settings
— Just-in-time (JIT) provisioning can automatically create MC user accounts on first login
User activation/deactivation: When employees leave, promptly deactivate their MC user account (cannot delete — only deactivate). Deactivated users cannot log in and are excluded from active user counts.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.