IdP Requirements for Salesforce.com Integrated Applications
Overview
Applications integrating with Salesforce, such as CPQ or Opportunity Detection, require that the username coming from the identity provider be the same as the username in the Salesforce organization. This is a mandatory requirement for data sync from Salesforce to such applications.
This is not an issue when the Salesforce organization is used as the identity provider connected to the Application Portal.
EXAMPLE 1: DEV ENVIRONMENT OF COMPANY FOO
- Salesforce org username suffix - @foo.com.dev
- External IdP username - @foo.com
- Username attribute of the external IdP must be in the format of @foo.com.dev
EXAMPLE 2: UAT ENVIRONMENT OF COMPANY FOO
- Salesforce org username suffix - @foo.com.uat
- External IdP username - @foo.com
- Username attribute of the external IdP must be in the format of @foo.com.uat
EXAMPLE 3: PROD ENVIRONMENT OF COMPANY FOO
- Salesforce org username suffix - @foo.com
- External IdP username - @foo.com
- Username attribute of the external IdP must be in the format of @foo.com
IdP Integration
SAML
SAML IdPs are capable of transforming claim values, which can be leveraged if available.
Example: DEV and UAT environments may append .dev and .uat to the username coming from the IdP. Refer to your IdP vendor documentation for exact steps.
ENTRA ID
Integrate Entra ID using SAML instead of OpenID connect. This requires an Entra ID Premium subscription.
SALESFORCE
Supported out of the box, no configuration needed.
