function readOnly(count){ }
Starting November 20, the site will be set to read-only. On December 4, 2023,
forum discussions will move to the Trailblazer Community.
+ Start a Discussion
Sk99Sk99 

SSO - Enable Multiple Config

Hi All,

 

I want to configure the 2nd Identity Provider for Single Sign On. As we have feature for multiple configuring the SSO(

https://login.salesforce.com/help/pdfs/en/salesforce_summer13_release_notes.pdf), I was trying to configure it.

But found that login url is going to be changed in the impact list

"Your Salesforce Login URL will change from https://test.salesforce.com/?saml=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx to https://test.salesforce.com?so=00Dxxxxxxxxxxxx. This may cause users to be unable to log in using SAML."

 

Does multiple configuration impact the existing configuration? If so how we can take the precautions and please let me know best practices for multiple configuration and steps.

 

Appreciate your help.

 

Thanks

digamber.prasaddigamber.prasad

Hi,

 

It should not impact existing configuration.

 

Let me know if you see otherwise.

 

Happy to discuss it further!

digamber.prasaddigamber.prasad

Also, Please take care of below too:-

 

"You will need to update the Assertion Consumer Service (ACS) URL used for Salesforce in your Identity Provider. Make this change when you begin using multiple SAML single sign-on configurations to avoid down time for users currently using single sign-on."

Sk99Sk99

Thank you Prasad for quick reply. I will try to configure and update you.

 

Thanks

digamber.prasaddigamber.prasad

Did you try it? Any luck with thi?

Sk99Sk99

Yes Prasad, I tried that, when we configure the Multi Config, it changes the Login Url and Token End Point of existing SSO config and we need to update the Identity Provider again.

 

Thanks

digamber.prasaddigamber.prasad

Cool!

tggagnetggagne

This was great information.  In an org I'm working on I simply went to the Customize->All Communities, and selected "Adminisration Settings" from the drop-down next to a community's name to enable SSO login.

All I need now is for the ADFS administrator to add the new URLs.