Configuring SAML SSO for Salesforce

These steps will guide you through setting up the single sign-on (SSO) functionality between ADSelfService Plus and Salesforce.

Prerequisite

  1. Make sure that HTTPS has been enabled on the ADSelfService Plus server.
  2. Log in to ADSelfService Plus as an administrator.
  3. Navigate to Configuration > Self-Service > Password Sync/Single Sign On > Add Application, and select Salesforce from the applications displayed.
  4. Note: You can also find the application that you need from the search bar located in the left pane or the alphabet-wise navigation option in the right pane.
  5. Click IdP details in the top-right corner of the screen.
  6. In the pop-up that appears, copy the Entity ID, Login URL and Logout URL, and download the metadata file by clicking on Download IdP Metadata.
  7. IdP details in ADSelfService Plus for Salesforce SSO

SalesForce (Service Provider) configuration steps

  1. Log in to Salesforce with administrator credentials.
  2. Note: The steps below pertain to the Salesforce Lightning platform.
  3. Click the Gear icon from the top-right corner.
  4. Salesforce setup for configuring SAML SSO via ADSelfService Plus

  5. Navigate to Settings (from the left panel menu) > Identity > Single Sign-On Settings.
  6. Salesforce setup panel overview while configuring SAML SSO via ADSelfService Plus

  7. Click Edit.
  8. Select SAML Enabled, then click Save.
  9. Salesforce SAML SSO via metadata file in ADSelfService Plus

  10. Now click New from Metadata File from the SAML Single Sign-On Settings.
  11. Salesforce SAML SSO via metadata file in ADSelfService Plus

  12. Upload the metadata file downloaded in the Step 5 of the prerequisite, then click Create.
  13. Modify the Name and API Name with easily recognizable names (for instance, SelfService) for reference.
  14.  Salesforce SAML SSO settings for ADSelfService Plus

  15. Click Save.
  16. Once done, copy the Login URL under Endpoints and click on Download Metadata to copy the Salesforce SP metadata.
  17. Salesforce SP SAML SSO settings for ADSelfService Plus

  18. Open the metadata file in a text editor. Locate the AssertionConsumerService parameter and copy it.
  19. Copying the Salesforce ACS URL for ADSelfService Plus

  20. To map the SSO Login URL to a specific domain login page:
    • Navigate to Settings (from the left panel menu) > Company Settings > My Domain.
    • Click Edit in the Edit Authentication Configuration of the desired domain.
    • Authentication configuration details in ADSelfService Plus for Salesforce SSO

    • Enable the SSO Configuration as an Authentication Service.
    •  Authentication service configuration details in ADSelfService Plus for Salesforce SSO

    • Click Save.

ADSelfService Plus (Identity Provider) configuration steps

  1. Now, switch to ADSelfService Plus’ Salesforce configuration page.
  2. Overview of ADSelfService Plus' SSO settings while configuring SAML SSO for Salesforce

  3. Enter the Application Name and Description.
  4. Enter the Domain Name of your Salesforce account. For example, if you use johndoe@thinktodaytech.com to log in to Salesforce, then thinktodaytech.com is the domain name.
  5. In the Assign Policies field, select the policies for which SSO need to be enabled.
  6. Note: ADSelfService Plus allows you to create OU and group-based policies for your AD domains. To create a policy, go to Configuration > Self-Service > Policy Configuration > Add New Policy.
  7. Under the SSO tab, select Enable Single Sign-On.
  8. Choose SAML from the Select Sign-on Method drop-down.
  9. Fill the SP Login Initiate URL field with the Login URL copied in step 10 of the SP configuration.
  10. Enter the Assertion Consumer Service URL copied in step 11 of the SP configuration in the Assertion Consumer Service URL field.
  11. Note: If your Salesforce metadata contains multiple Assertion Consumer URLs, click the + button next to the text field to add all of them.
  12. In the Name ID Format field, choose the format for the user login attribute value specific to the application.
  13. Note: Use Unspecified as the default option if you are unsure about the format of the login attribute value used by the application.
  14. Click Add Application.
  15. Your users should now be able to sign in to Salesforce through ADSelfService Plus.
Note: For Salesforce, both the IdP-initiated and SP-Initiated flows are supported.
Go to Top

Thanks!

Your request has been submitted to the ADSelfService Plus technical support team. Our technical support people will assist you at the earliest.

 

Need technical assistance?

  • Enter your email ID
  • Talk to experts
  •  
     
  •  
  • By clicking 'Talk to experts' you agree to processing of personal data according to the Privacy Policy.

Don't see what you're looking for?

  •  

    Visit our community

    Post your questions in the forum.

     
  •  

    Request additional resources

    Send us your requirements.

     
  •  

    Need implementation assistance?

    Try OnboardPro

     

Copyright © 2025, ZOHO Corp. All Rights Reserved.