Salesforce - SAML IDR SSO Configuration RSA Ready Implementation Guide
Originally Published: 2023-06-08
This section describes how to integrate Salesforce with RSA Cloud Authentication Service using IDR SSO.
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as an IDR SSO to Salesforce.
Procedure
- Log on to RSA Cloud Administration Console and navigate to Applications > Application Catalog.
- Search for Salesforce.com and click Add to add the connector.
- On the Basic Information page, enter the name for the application in the Name field, and click Next Step.
- Choose Identity Router and click Next Step.
- Navigate to the Initiate SAML Workflow section.
In the Connection URL field, verify the default setting.
- Choose IDP-initiated or SP-Initiated.
- Scroll down to the SAML Identity Provider (Issuer) section.
- Identity Provider URL is automatically generated.
- Issuer Entity ID is automatically generated.
- Click Choose File and upload the private key.
- Click Choose File to import the public signing certificate.
- Select the Include Certificate in Outgoing Assertion check box.
- In the Service Provider section and enter following details:
- Assertion Consumer Service (ACS) - https://< Current My Domain URL from Salesforce>
- Audience (Service Provider Issuer ID) - https://< Current My Domain URL from Salesforce >
- Scroll down to the user identity section and select the following:
- Identifier Type – unspecified
- Identity Source – select your user identity source.
- Property – mail
- Click Next Step.
- On the User Access page, select the access policy that the identity router will use to determine which users can access the application.
- Click Next Step.
- On the Portal Display page, configure the portal display and other settings.
- Click Save and Finish.
- Click Publish Changes.
- Navigate to Applications > My Applications.
- Locate your Salesforce application instance in the list and from the Edit option, and click Export Metadata.
Note: The preceding two steps are applicable only if export metadata is required.
Configure Salesforce
Perform these steps to configure Salesforce.
Procedure
- Log on to Salesforce admin console. https://login.salesforce.com
- Click Switch to Lightning Experience if you are using Salesforce classic.
- Click the gear icon on the upper-right corner, and click Service Setup.
- In the left pane, click Single Sign-On Settings under the Identity section.
- Click Edit and select SAML Enabled if not selected already.
- Click New or New from Metadata File.
- If you clicked New from Metadata File, then select the metadata file downloaded from Idp, and click Create.
- If clicked New, add the details and click Save.
- In the Name field, enter a name for this Authentication Service profile.
- Click in the API Name field, the name from the Name field is automatically populated..
- In the Issuer field, enter the Identity Provider Entity ID for an IDR integration or https://<rsa_tenant>.auth.securid.com/saml-fe/sso for a Cloud IdP integration.
- In the Entity ID field, enter an ID that starts with https://, for example, https://<instance>.my.salesforce.com. This must match the Audience (Service Provider Entity ID) field on the RSA SecurID Access.
- In Identity Provider Certificate, click Browse and select RSA SecurID Access public certificate.
- In SAML Identity Type, select Assertion contains User’s Salesforce.com username.
- In SAML Identity Location, select Identity is in the NameIdentifier element of the Subject statement.
- In Service Provider Initiated Request Binding, select HTTP Redirect for an IDR integration and HTTP POST for a Cloud IdP integration.
- Click My Domain under Company Settings.
- Click Edit under Authentication Configuration.
- Under Authentication Configuration, select the single sign on setting configured.
Note: If your environment requires SP signing, click Download Metadata, return to the RSA console, and edit the connector to import the metadata file, which will import the certificate.
- Navigate to Settings > Company Settings > Authentication Configuration, and click Edit.
- Select the check box next to the Authentication Service which corresponds to your RSA configuration, and click Save.
Note: Clear the check boxes for Login Form and other services to prevent side door access.
Note on My Domain URL
The current My Domain URL value can be found in My Domain under Company Settings.
Configuration is complete.
Return to main page .
Related Articles
Salesforce - SAML My Page SSO Configuration - RSA Ready Implementation Guide 66Number of Views Workday - SAML Relying Party Configuration - RSA Ready Implementation Guide 4Number of Views Workday - SAML My Page SSO Configuration - RSA Ready Implementation Guide 2Number of Views Skyhigh End User Remediation Flow - SAML My Page SSO Configuration - RSA Ready Implementation Guide 21Number of Views Salesforce - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 104Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) How to install the jTDS JDBC driver on WildFly for use with Data Collections in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.8 Setup and Configuration Guide Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?