Quantcast
Channel: Azure Active Directory forum
Viewing all articles
Browse latest Browse all 16000

Azure AD SSO with SalesForce.com ot working for a environment witth ADFS 2.0 in place

$
0
0

Scenario

The environment has below setup.

  • On-premise Exchange Server (Decommissioned after migration)
  • ADFS 2.0 setup with Dir Sync.
  • Office 365 Tenant.
  • ADFS 2.0 provides Federation for yammer and some other on premise apps.
  • Write back has been enabled for DirSync.

The main SMTP domain of the client has been federated along with 6 other domains.

Application configuration as follow.

Requirement

Users need to access salesforce by using myapps.microsoft.com without entering their salesforce credentials (Azure Federated Identity)

Issue

When a user logs in to myapps.microsoft.com and clicks SalesForce application he is redirected to the correct URL but SSO doesn’t happen. This happens for both cloud only (*.onmicrosoft.com) and on premise users.

Troubleshooting

  • Configured same on a test Azure & Office 365 environment which doesn’t have ADFS. It works perfectly.
  • In Salesforce cannot validate SAML response for the customer setup but in test setup SAML validation works fine.

Questions

  1. Is there any way we can bypass ADFS for this particular federated domain and use AAD as the authentication provider for salesforce?
  2. Is above possible with Azure Access Control Service?
  3. The organization needs ADFS to authenticate their on-premise applications. If Azure ADFS Proxy was introduced can this be addressed?
  4. Is there any way that we can configure federation for SalesForce on ADFS and allow the users to access it via myapps.microsoft.com?

Janaka Rangama MCT MIEEE MBCS (Please take a moment to Vote as Helpful and/or Mark as Answer, where applicable.)


Viewing all articles
Browse latest Browse all 16000

Trending Articles