What is the difference between federated and delegated authentication, and when would you actually recommend delegated?
Suggested answer
In federated authentication the identity provider authenticates the user and sends Salesforce a signed assertion. Salesforce never receives the password. That is SAML, and it is the default recommendation.
In delegated authentication the user types their password into Salesforce, and Salesforce makes an outbound SOAP callout to a web service you host, passing the username, the password, and the source IP. Your service returns true or false.
I recommend delegated authentication in one situation: the credential store can only be queried, not federated with — a legacy system with no SAML or OpenID Connect capability — and the population is small enough that the added risk is contained. Two consequences have to be stated out loud when I do. First, the password is now transiting Salesforce, which is exactly what federation avoids. Second, that endpoint is now on the critical path for login: if it is slow or down, those users cannot get in at all, so its availability target becomes an authentication requirement. It is enabled per user through the single sign-on permission on a profile or permission set, which at least lets me scope it to the population that needs it rather than the whole org.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.