Salesforce - SAML My Page SSO Configuration - RSA Ready Implementation Guide
Originally Published: 2023-06-07
This article describes how to integrate Salesforce with RSA Cloud Access Service (CAS) using My Page SSO.
Configure CAS
Perform these steps to configure CAS using My Page SSO.
Procedure
- Sign in to the RSA Cloud Administration Console and browse to Applications > Application Catalog.
- Click Create from Template, and then click the Select next to SAML Direct.
- On the Basic Information page, choose Cloud.
- Enter the name for the application and click Next Step.
- On the Connection Profile page, navigate to the Initiate SAML Workflow section and choose IdP-initiated.
- Under Data Input Method, choose Import Metadata and click Choose File to import the metadata downloaded from Salesforce to populate the ACS URL and Service Provider Entity ID.
- In the Message Protection section, select IdP signs entire SAML response.
- Click Download Certificate.
- Under the User Identity section:
- Identifier Type: unspecified
- Property: mail
- In the Statement Attributes section, enter the following Authentication Context.
mfa
Note: The Authentication Context value is explicitly recognized by Salesforce as a secure authentication method and indicates that a contracted mobile-based two-factor authentication flow was performed by the Identity Provider.
Reference: Salesforce SFDCAV Device Activation Function Guide: Changes to Device Activation for Single Sign-On (SSO) Logins
If you want to bypass the Device Activation, the device needs to pass the Authentication context values as mfa. - On the User Access page, choose the access policy you want to use to determine which users can access the application, and then click Next Step.
- On the Portal Display page, configure the portal display and other settings, and then click Next Step.
- On the Fulfillment page, configure your preferred settings or leave the Fulfillment toggle disabled as it is, and then click Save and Finish.
- Click Publish Changes and wait for the operation to be completed.
After publishing, your application is now enabled for SSO. - Navigate to the newly created application from My Application.
- In the Edit drop-down list, choose Export Metadata. This metadata will be used later in the Salesforce configuration.
Configure Salesforce
Perform these steps to configure Salesforce.
Procedure
- Log in to the Salesforce tenant with an administrator account.
- Click the gear icon and click Open Advanced Setup.
- In the left pane, search for Single Sign-On Settings under the Identity section and click it.
- Click Edit and select the SAML Enabled checkbox, if not selected already, and then click Save.
- Choose the metadata file downloaded from RSA and click Create.
- Add the downloaded IdP certificate and click Save.
- Click Download Metadata.
- Navigate to My Domain under Company Settings.
- Click Edit under Authentication Configuration, select the checkbox with your configuration name, and then click Save.
The configuration is complete.
Related Articles
Salesforce - SAML IDR SSO Configuration RSA Ready Implementation Guide 56Number of Views Workday - SAML Relying Party Configuration - RSA Ready Implementation Guide 4Number of Views Workday - SAML My Page SSO Configuration - RSA Ready Implementation Guide 2Number of Views Skyhigh End User Remediation Flow - SAML My Page SSO Configuration - RSA Ready Implementation Guide 21Number of Views How to SecurID-protect OWA using single sign-on (SSO) when OWA is in a cluster 203Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) Artifacts to gather in RSA Identity Governance & Lifecycle RSA MFA Agent 2.4.3 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.8 Setup and Configuration Guide
Don't see what you're looking for?