Delegated Single Sign-On using OneLogin for Browser and Salesforce Mobile app
Delegated SSO configuration using OneLogin requires performing the following:
- Configuring the Identity Provider (OneLogin)
- Activating Delegated Authentication for Salesforce
- Configuring the Service Provider (Salesforce)
- Configuring the Service Provider for Delegated Authentication on Salesforce mobile app
- Verifying the Single Sign-On Configuration with Delegated SSO using OneLogin
Configuring the Identity Provider (OneLogin)
For delegated authentication, there is no additional configuration required.
To configure the Identity Provider, refer to the following:
Activating Delegated Authentication for Salesforce
For activating delegated authentication for your Salesforce org, please see this link.
Configuring the Service provider (Salesforce)
To configure the Service Provider (Salesforce):
- Login to Salesforce.
- Click Setup. A left pane displaying various sections appears.
- In the Administration Setup section, expand Security Controls and click Single Sign-On Settings. Single Sign-on Settings Page appears
The Single Sign-On Settings page
(Click the image to expand it.) - Click Edit. The page reloads enabling the Delegated Authentication and Federated Single Sign-On Using SAML sections.
The Single Sign-On page displaying the enabled sections
(Click the image to expand it.) - In the Delegated Authentication section, enter the following Delegated Gateway URL: https://app.onelogin.com/delegation/?app=salesforce
- In the Federated Single Sign-On Using SAML section, select SAML Enabled.
- Click Save. The URL is saved.
- Click Setup. A left pane displaying various sections appears.
- In the Administration Setup section, expand Manage Users and click Profiles. The User Profiles page appears.
The User Profiles page
(Click the image to expand it.) - Click the required name on the user profile. The Profile Detail of the selected user appears.
The Profile Detail of the selected user
(Click the image to expand it.) - Click Edit. The Profile Edit page appears.
The Profile Edit page
(Click the image to expand it.) - In the Administrative Permissions section, select Is Single Sign-On Enabled.
- Click Save.
Configuring the Service Provider for Delegated Authentication on Salesforce Mobile application
To Configure Service Provider for Delegated Authentication on Salesforce Mobile application:
- Refer to Step 8 to Step 11.
- In the Connected Apps Access section, select Salesforce1/Chatter for Android.
- Click Save.
Verifying the Single Sign-On Configuration with Delegated SSO using OneLogin
You can verify the configuration for delegated Single Sign-On for Browser and Salesforce Mobile Application.
Verifying the Configuration for Browser
To verify the configuration for browser:
- Enter the required Salesforce login URL in a browser.
- Enter your Identity Provider credentials.
The IDP credentials are sent to the Delegated Gateway URL specified in Single Sign-On Settings for validation.
Verifying the Configuration for Salesforce Mobile Application
To verify the configuration for Salesforce Mobile Application:
- Open the Salesforce Mobile Application on your mobile.
- Enter your Identity Provider credentials on the login screen.
- Re-enter your Identity Provider credentials on the Salesforce login page. The IDP credentials are sent to the Delegated Gateway URL specified in Single Sign-On Settings for validation. For more information, see Logging into Salesforce mobile app.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*