Integrating a Salesforce Community Site in Okta
Last Updated:
Overview
Integrating a Salesforce Community site in Okta requires creating a new Salesforce.com integration, even if one already exists. Administrators must configure the application settings, set up Security Assertion Markup Language (SAML) 2.0 for Single Sign-On (SSO), and enable provisioning with the correct Salesforce Account ID.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Salesforce Community
- Single Sign-On (SSO)
Solution
How is a Salesforce Community site integrated in Okta?
Add the Salesforce.com application from the integration catalog, configure the general settings for a community user, set up SAML 2.0 for SSO, and enable provisioning with the correct Salesforce Account ID, as detailed in either the video demonstration or the written instructions.
NOTE: When integrating a Salesforce Community in Okta, a new Salesforce.com integration is required even if a Salesforce.com integration already exists.
- On the Okta Admin Console, navigate to Applications > Applications.
- Click Browse App Catalog.
- Search for Salesforce.com and click Add Integration.
- In step 1 of the Salesforce integration, configure the General Settings by entering an Application Label such as "Salesforce Community", entering a custom Salesforce domain, and selecting the User Profile & Type. Select "Salesforce Community User" for the User Profile & Type and click Next.
-
In step 2 of the Salesforce integration, select the Sign-On options. Click SAML 2.0 to set up SSO, then click View Setup Instructions and follow the instructions to finish configuring SSO for the Salesforce Community site. In the Advanced Sign-on Settings section, enter the Login URL for the Salesforce Community Site. This is the Login URL in Salesforce listed under For Communities.
- Enable provisioning to the Salesforce community site by following the instructions presented in the provided link.
- Once the provisioning integration is successfully configured, navigate to the To App tab under the Provisioning tab.
- Click Edit and set the Salesforce Account ID to the account associated with the Community site in Salesforce. This is the ID of the Salesforce Account with which provisioned external users should be associated.
The Salesforce Account ID is located in the URL of the profile in Salesforce, as shown in the following image.
The Salesforce Community integration is now complete.
