Skip to content

Commit 6a70ecb

Browse files
authored
Merge pull request #99639 from v-nagta/salesforceupdate
Product Backlog Item 884800: SaaS App Tutorial: Salesforce update
2 parents 6bb09cb + fe0e0f2 commit 6a70ecb

File tree

2 files changed

+37
-36
lines changed

2 files changed

+37
-36
lines changed
18.9 KB
Loading

articles/active-directory/saas-apps/salesforce-tutorial.md

Lines changed: 37 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -1,25 +1,25 @@
11
---
2-
title: 'Tutorial: Azure Active Directory Single sign-on (SSO) integration with Salesforce | Microsoft Docs'
2+
title: 'Tutorial: Azure Active Directory single sign-on (SSO) integration with Salesforce | Microsoft Docs'
33
description: Learn how to configure single sign-on between Azure Active Directory and Salesforce.
44
services: active-directory
55
documentationCenter: na
66
author: jeevansd
7-
manager: daveba
7+
manager: mtillman
88
ms.reviewer: barbkess
99

1010
ms.assetid: d2d7d420-dc91-41b8-a6b3-59579e043b35
1111
ms.service: active-directory
1212
ms.subservice: saas-app-tutorial
1313
ms.workload: identity
1414
ms.tgt_pltfrm: na
15-
ms.devlang: na
1615
ms.topic: tutorial
17-
ms.date: 08/13/2019
16+
ms.date: 12/23/2019
1817
ms.author: jeedes
1918

2019
ms.collection: M365-identity-device-management
2120
---
22-
# Tutorial: Azure Active Directory Single sign-on (SSO) integration with Salesforce
21+
22+
# Tutorial: Azure Active Directory single sign-on (SSO) integration with Salesforce
2323

2424
In this tutorial, you'll learn how to integrate Salesforce with Azure Active Directory (Azure AD). When you integrate Salesforce with Azure AD, you can:
2525

@@ -66,27 +66,23 @@ Configure and test Azure AD SSO with Salesforce using a test user called **B.Sim
6666
To configure and test Azure AD SSO with Salesforce, complete the following building blocks:
6767

6868
1. **[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
69-
1. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
70-
1. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
71-
2. **[Configure Salesforce SSO](#configure-salesforce-sso)** - to configure the Single Sign-On settings on application side.
72-
1. **[Create Salesforce test user](#create-salesforce-test-user)** - to have a counterpart of B.Simon in Salesforce that is linked to the Azure AD representation of user.
73-
3. **[Test SSO](#test-sso)** - to verify whether the configuration works.
69+
* **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
70+
* **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
71+
1. **[Configure Salesforce SSO](#configure-salesforce-sso)** - to configure the single sign-on settings on application side.
72+
* **[Create Salesforce test user](#create-salesforce-test-user)** - to have a counterpart of B.Simon in Salesforce that is linked to the Azure AD representation of user.
73+
1. **[Test SSO](#test-sso)** - to verify whether the configuration works.
7474

7575
## Configure Azure AD SSO
7676

77-
In this section, you enable Azure AD single sign-on in the Azure portal.
78-
79-
To configure Azure AD single sign-on with Salesforce, perform the following steps:
80-
8177
Follow these steps to enable Azure AD SSO in the Azure portal.
8278

83-
1. In the [Azure portal](https://portal.azure.com/), on the **Salesforce** application integration page, find the **Manage** section and select **Single sign-on**.
84-
1. On the **Select a Single sign-on method** page, select **SAML**.
85-
1. On the **Set up Single Sign-On with SAML** page, click the edit/pen icon for **Basic SAML Configuration** to edit the settings.
79+
1. In the [Azure portal](https://portal.azure.com/), on the **Salesforce** application integration page, find the **Manage** section and select **single sign-on**.
80+
1. On the **Select a single sign-on method** page, select **SAML**.
81+
1. On the **Set up single sign-on with SAML** page, click the edit/pen icon for **Basic SAML Configuration** to edit the settings.
8682

8783
![Edit Basic SAML Configuration](common/edit-urls.png)
8884

89-
1. On the **Basic SAML Configuration** section, perform the following steps:
85+
1. On the **Basic SAML Configuration** section, enter the values for the following fields:
9086

9187
a. In the **Sign-on URL** textbox, type the value using the following pattern:
9288

@@ -103,11 +99,11 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
10399
> [!NOTE]
104100
> These values are not real. Update these values with the actual Sign-on URL and Identifier. Contact [Salesforce Client support team](https://help.salesforce.com/support) to get these values.
105101

106-
1. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, click **Download** to download the **Federation Metadata XML** from the given options as per your requirement and save it on your computer.
102+
1. On the **Set up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Federation Metadata XML** and select **Download** to download the certificate and save it on your computer.
107103

108104
![The Certificate download link](common/metadataxml.png)
109105

110-
1. On the **Set up Salesforce** section, copy the appropriate URL(s) as per your requirement.
106+
1. On the **Set up Salesforce** section, copy the appropriate URL(s) based on your requirement.
111107

112108
![Copy configuration URLs](common/copy-configuration-urls.png)
113109

@@ -122,9 +118,6 @@ In this section, you'll create a test user in the Azure portal called B.Simon.
122118
1. In the **User name** field, enter the [email protected]. For example, `[email protected]`.
123119
1. Select the **Show password** check box, and then write down the value that's displayed in the **Password** box.
124120
1. Click **Create**.
125-
126-
> [!NOTE]
127-
> Salesforce user attributes are case sensitive for SAML validation.
128121

129122
### Assign the Azure AD test user
130123

@@ -146,48 +139,56 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
146139

147140
## Configure Salesforce SSO
148141

149-
1. Open a new tab in your browser and sign in to your Salesforce administrator account.
142+
1. To automate the configuration within Salesforce, you need to install **My Apps Secure Sign-in browser extension** by clicking **Install the extension**.
143+
144+
![My apps extension](common/install-myappssecure-extension.png)
145+
146+
1. After adding extension to the browser, click on **Set up Salesforce** will direct you to the Salesforce Single Sign-On application. From there, provide the admin credentials to sign into Salesforce Single Sign-On. The browser extension will automatically configure the application for you and automate steps 3-13.
147+
148+
![Setup configuration](common/setup-sso.png)
149+
150+
1. If you want to setup Salesforce manually, open a new web browser window and sign into your Salesforce company site as an administrator and perform the following steps:
150151

151-
2. Click on the **Setup** under **settings icon** on the top right corner of the page.
152+
1. Click on the **Setup** under **settings icon** on the top right corner of the page.
152153

153154
![Configure Single Sign-On](./media/salesforce-tutorial/configure1.png)
154155

155-
3. Scroll down to the **SETTINGS** in the navigation pane, click **Identity** to expand the related section. Then click **Single Sign-On Settings**.
156+
1. Scroll down to the **SETTINGS** in the navigation pane, click **Identity** to expand the related section. Then click **Single Sign-On Settings**.
156157

157158
![Configure Single Sign-On](./media/salesforce-tutorial/sf-admin-sso.png)
158159

159-
4. On the **Single Sign-On Settings** page, click the **Edit** button.
160+
1. On the **Single Sign-On Settings** page, click the **Edit** button.
160161

161162
![Configure Single Sign-On](./media/salesforce-tutorial/sf-admin-sso-edit.png)
162163

163164
> [!NOTE]
164165
> If you are unable to enable Single Sign-On settings for your Salesforce account, you may need to contact [Salesforce Client support team](https://help.salesforce.com/support).
165166
166-
5. Select **SAML Enabled**, and then click **Save**.
167+
1. Select **SAML Enabled**, and then click **Save**.
167168

168-
![Configure Single Sign-On](./media/salesforce-tutorial/sf-enable-saml.png)
169+
![Configure Single Sign-On](./media/salesforce-tutorial/sf-enable-saml.png)
169170

170-
6. To configure your SAML single sign-on settings, click **New from Metadata File**.
171+
1. To configure your SAML single sign-on settings, click **New from Metadata File**.
171172

172173
![Configure Single Sign-On](./media/salesforce-tutorial/sf-admin-sso-new.png)
173174

174-
7. Click **Choose File** to upload the metadata XML file which you have downloaded from the Azure portal and click **Create**.
175+
1. Click **Choose File** to upload the metadata XML file which you have downloaded from the Azure portal and click **Create**.
175176

176177
![Configure Single Sign-On](./media/salesforce-tutorial/xmlchoose.png)
177178

178-
8. On the **SAML Single Sign-On Settings** page, fields populate automatically and click save.
179+
1. On the **SAML Single Sign-On Settings** page, fields populate automatically and click save.
179180

180181
![Configure Single Sign-On](./media/salesforce-tutorial/salesforcexml.png)
181182

182-
9. On the left navigation pane in Salesforce, click **Company Settings** to expand the related section, and then click **My Domain**.
183+
1. On the left navigation pane in Salesforce, click **Company Settings** to expand the related section, and then click **My Domain**.
183184

184185
![Configure Single Sign-On](./media/salesforce-tutorial/sf-my-domain.png)
185186

186-
10. Scroll down to the **Authentication Configuration** section, and click the **Edit** button.
187+
1. Scroll down to the **Authentication Configuration** section, and click the **Edit** button.
187188

188189
![Configure Single Sign-On](./media/salesforce-tutorial/sf-edit-auth-config.png)
189190

190-
11. In the **Authentication Configuration** section, Check the **AzureSSO** as **Authentication Service** of your SAML SSO configuration, and then click **Save**.
191+
1. In the **Authentication Configuration** section, Check the **AzureSSO** as **Authentication Service** of your SAML SSO configuration, and then click **Save**.
191192

192193
![Configure Single Sign-On](./media/salesforce-tutorial/sf-auth-config.png)
193194

@@ -237,4 +238,4 @@ When you click the Salesforce tile in the Access Panel, you should be automatica
237238

238239
- [Configure User Provisioning](salesforce-provisioning-tutorial.md)
239240

240-
- [Try Salesforce with Azure AD](https://aad.portal.azure.com)
241+
- [Try Salesforce with Azure AD](https://aad.portal.azure.com)

0 commit comments

Comments
 (0)