Suggested answer

Four steps, in order.

1. Ensure My Domain is deployed, then enable Salesforce as an Identity Provider and choose the certificate that will sign assertions — self-signed is fine, and its expiry goes straight into the rotation calendar.
2. Get the service provider's values from the vendor: Entity ID, Assertion Consumer Service URL, the Name ID format they expect, and any attributes they need.
3. Create a connected app with SAML enabled and enter those values, choosing the subject type — username, Federation ID, User ID, or a custom formula — that matches how the vendor identifies users on their side.
4. Assign the connected app through a profile or permission set. This is what makes the tile appear in the App Launcher and what actually authorises the user; without it the configuration exists but nobody can use it.

Then I test both directions — identity-provider-initiated from the App Launcher, and service-provider-initiated from the vendor's own login page — and use the Identity Provider Event Log to diagnose anything that fails, since that is where Salesforce records the assertions it issued.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.