Step 1 - Email Us
Send an email to support@trusona.com. In the body include:
- Your company name and
- Email address domain associated with your Salesforce account, e.g. "mydomain.com" if your email address is "me@mydomain.com"
Trusona will use this information to generate an .xml file. Trusona will email that file back which is needed to complete Trusona for Salesforce integration. (You can expect to receive an email from Trusona within 24hrs)
Step 2 - Custom Domain
Create a custom domain in Salesforce:
Setup > Domain Management > My Domain > "Create your custom domain" > Register Domain
Note: Once your domain is registered it will be up to the organization's policy whether to still allow logging into salesforce through login.salesforce.com and/or only allow login through the organization's new customized domain.
Step 3 - Enable SAML
Make sure that "SAML enabled" is checked. Setup > Quick Find search Single Sign-On Settings > Edit > check SAML Enabled > Save
Trusona support must send you an .xml file before continuing to Step 4
Step 4 - Upload Trusona's .xml
While in Single Sign-On Settings
- Select "New from Metadata file" button.
- Choose File
- Upload the .xml file Trusona sent you
- Select Create
Step 5 - Edit SAML Gateway
While still in Single Sign-On Settings
- Select Edit
- Change Name to Trusona
- Confirm Request Signature Method is set to "RSA-SHA256"
- Option 1: Select "Assertion Contains the User's Salesforce username" if the Salesforce username is the same as their organization's email address used to login to Salesforce. To verify if the Salesforce username is the same as their organization's email address used to login to Salesforce go to Setup > Users > Users. If yes, the username and their organization's email address should be the same.
- Option 2: If the Salesforce username is different from their organization's email than select "Assertion contains the Federation ID from the user object" and a Federation ID will then need to be created for each user (see step 5B).
- Select HTTP Redirect
- Make sure Identity Provider Login URL is populated
- Select Save
Step 5B - Creating a Federation ID (Only needed if you selected Option 2 in the previous step)
Note: The XML file provided by Trusona is customized to your organizations's email domain. If your users have a different email domain as their username than you will need to create link between their email domain and the organizations' by creating a Federation ID for those users.
- Setup > Manage Users > Users > edit next to the user's name.
- Enter the email address the Salesforce user uses to login to Salesforce in the Federation ID field
Step 6 - Email Trusona .xml
- In Single Sign-On Settings select “Trusona” under Name.
- Select "Download Metadata" and send that .xml file to support@trusona.com.
Trusona is going to send you back a confirmation email that you are ready to Login using Trusona with Salesforce.
Step 7 - Check off Trusona
Setup > Quick Find search My Domain > Edit in Authentication Configuration >
check off Trusona > Save