function readOnly(count){ }
Starting November 20, the site will be set to read-only. On December 4, 2023,
forum discussions will move to the Trailblazer Community.
+ Start a Discussion
Kevin BlumenfeldKevin Blumenfeld 

Is there a way to make SSO work from mydomain.my.salesforce.com instead of https://adfs.contoso.com/adfs/ls/idpinitiatedsignon.aspx?loginToRp=https://saml.salesforce.com ?

I would like it to be more of a seamless experience. Am I missing a step?
 

Thank you.

Best Answer chosen by Kevin Blumenfeld
JLA.ovhJLA.ovh
Yes, think about a Service Provider (Salesforce) initiated flow. When trying to access Salesforce, if Salesforce has no valid session, your user will be redirected to your identity provider (adfs.contoso.com) with a SAML request, then adfs will authenticate the user and provide a SAML response to Salesforce, granting access. To avoid a login screen on Salesforce, configure the attributes of your my domain to allow only your sso configuration and not login password