Salesforce Decode
Salesforcedecode
Back to questions
Salesforce ArchitectureArchitect (Hardest)identitymulti-orgsso

Design enterprise identity federation architecture across twelve Salesforce orgs

Real World Scenario

Employee accesses 4 of 12 Salesforce orgs; duplicate accounts and password fatigue drive SSO federation project.

Expected Answer

• Single IdP Azure AD Okta SAML all orgs • SCIM provisioning automate user lifecycle all orgs • FederationIdentifier consistent key cross-org • Org access entitlement IdP group mapping • Integration users excluded separate vault credential • Experience Cloud external identity separate B2B B2C flows • Annual access certification all orgs consolidated report

Follow-Up Questions & Answers

Click to expand — each follow-up includes a direct, interview-ready answer

Direct answer: Single IdP Azure AD Okta SAML all orgs Also consider: SCIM provisioning automate user lifecycle all orgs In practice: FederationIdentifier consistent key cross-org Document the decision in an ADR and align with enterprise standards.

Architect Perspective

12 orgs without federation is 12 password problems—SCIM plus SAML enterprise mandatory.