What SSO options are available for Experience Cloud and how is SAML 2.0 configured?
Suggested answer
Experience Cloud supports multiple SSO options:
1. SAML 2.0 — enterprise SSO where an external Identity Provider (IdP such as Okta, Azure AD) authenticates the user and passes a SAML assertion to Salesforce. Configuration requires: IdP metadata (Entity ID, SSO URL, certificate) in Salesforce, and Salesforce SP metadata exported to the IdP.
2. Social Sign-On — authenticate via Facebook, Google, or Microsoft using OAuth 2.0. Configured via Auth Provider records in Setup; each provider requires a Client ID/Secret from the social platform's developer console.
3. Auth Provider + Registration Handler — when a new user authenticates via Social Sign-On for the first time, an Apex Registration Handler class is invoked to create or match a Salesforce user record, assign a profile, and optionally link to an existing Contact/Account.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.