Single sign-on (SSO) is a highly secure, time-saving user authentication process. SSO lets users access multiple applications with a single account and sign out instantly with a single click.
TalentLMS supports SSO. To facilitate single sign-on on your domain, TalentLMS acts as a service provider (SP) through the SAML (Security Assertion Markup Language) standard.
You can create an SSO integration between TalentLMS and Salesforce so that your Salesforce users can authenticate and log in to TalentLMS via SSO.
Phase 1. Enabling Salesforce as an Identity Provider
1. Log in to Salesforce as an administrator.
2. From Setup, in the Quick Find box (1), type “Identity Provider”, then select Identity Provider (2).
3. Click Enable Identity Provider (3).
4. Select a certificate from the drop-down menu, or create a new one.
5. Save your changes.
6. Note down the Issuer URL (4), which you will need later when configuring the External Client App.
7. Click Download Certificate (5). You will need this certificate later when configuring the TalentLMS SSO form.
Phase 2. Creating an External Client App for SAML 2.0
1. Log in to Salesforce as an administrator.
2. Go to the Salesforce Setup page.
3. From Setup, in the Quick Find box, type “external client apps”.
4. Select External Client App Manager, and click New External Client App.
5. In the Basic Information (1) section, enter your information in the External Client App Name (2), API Name (3), and Contact Email (4) fields. You can name the app as you like (e.g. TalentlmsSSO). This is how the app will appear in the App Launcher later.
6. Under the Web App (Enable SAML Settings) (5) section, select the Enable SAML (6) checkbox.
7. Enter your TalentLMS SP metadata as shown below, replacing yourdomain with the name of your TalentLMS portal:
- Entity ID (7): yourdomain.talentlms.com
- ACS URL (8): https://yourdomain.talentlms.com/simplesaml/module.php/saml/sp/saml2-acs.php/yourdomain.talentlms.com
*If you want to enable Single Logout, select the Enable Single Logout (9) checkbox and enter your following URL in the Single Logout URL field (10):
https://yourdomain.talentlms.com/simplesaml/module.php/saml/sp/saml2-logout.php/yourdomain.talentlms.com
Select “HTTP Redirect” as the Single Logout Binding (11).
8. From the IdP Certificate (12) drop-down menu, select the certificate you used earlier in Phase 1, Step 4.
9. Click Create (13) at the bottom of the page.
10. In your new External Client App, expand the App Policies section and click Edit.
11. For the Start Page, select Custom (14).
12. In the Custom Start URL (15) field, enter: https://yourdomain.talentlms.com/index/ssologin/service:saml
13. From the Available Profiles (16) list, select your preferred profiles and add them to the Selected Profiles (17) list on the right (e.g., System Administrator, Standard User, and Standard Platform User).
14. In TalentLMS, the four mandatory fields for SSO are First name, Last name, Email, and Username.
Salesforce automatically creates attributes for Username and Email for the SSO External Client App, but you will need to add attributes for First name and Last name.
15. Scroll down to Custom Attributes and click the plus icon (+) for Add.
16. In the Attribute Key (18) field, enter the name of the attribute, e.g., firstname.
17. In the Attribute Value (19) field, navigate to $User > First Name (20), and click Save.
18. Add another custom attribute for Last Name, following the same method outlined above.
| Note: If you need to add custom attributes to the SAML External Client App (for example, to map custom user fields), you can do so using the Custom Attributes option described above. The value in the Attribute Key field must match the name of the corresponding TalentLMS custom field. |
19. Expand the SAML Login Info (21) section. Then, note down the SP-Initiated Redirect Endpoint (22) and Single Logout Endpoint URLs (23), which you will need in Phase 3 when configuring the SSO form in your portal.
| Note: If you are setting up SSO for an Experience site, expand the For Experience Cloud, and note down the SP-Initiated Redirect Endpoint and Single Logout Endpoint URLs. |
20. Click Save (24).
Phase 3. Setting up SSO in TalentLMS
1. Sign in to your TalentLMS account as an administrator, go to Account & Settings > Users, and click SSO.
| Note: If you want to configure SSO for a branch: i. Go to Home > Branches. ii. Select the branch you want to update. iii. Go to the Info tab and then to the Users section. iv. Click Single Sign-On (SSO). |
2. From the SSO integration type drop-down menu, select SAML 2.0 (1).
3. Enter your Salesforce metadata as follows:
- Identity provider (IdP) (2): Enter the Issuer URL from Phase 1, Step 6.
- Certificate fingerprint: Open the certificate you downloaded in Phase 1, Step 7 using a text editor such as Notepad. Copy the contents of the file, then click Paste SAML certificate (PEM format) (3) and paste the PEM certificate into the SAML certificate (4) text box.
- Remote sign-in URL: Enter the SP-Initiated Redirect Endpoint from Phase 2, Step 20.
- Remote sign-out URL: Enter the Single Logout Endpoint from Phase 2, Step 20.
4. For Attribute mapping, you can select the appropriate attributes for the corresponding fields in TalentLMS. The four mandatory attributes are First name, Last name, Email, and Username.
Based on the attribute-mapping example in Phase 2, Steps 18-19, use the following:
- Username: email
- First name: firstname
- Last name: lastname
- Email: email
5. Click Save and check configuration (5). You will be redirected to Salesforce to authenticate and then back to TalentLMS, where a page will display the mapped attributes and values, as well as all attributes and values sent by Salesforce in the SAML response. If everything looks correct, the integration is complete.
6. Review the SSO configuration results:
- Under Attribute names defined in TalentLMS (6), confirm that the four mandatory attributes - TargetedID (username), First name, Last name, and Email - have a green checkmark. This indicates that TalentLMS received the attributes configured in the SSO settings.
- Under Attribute name/value pairs sent by your IdP (7), review the attributes and values sent by Salesforce. A green checkmark appears next to the attributes that match the mandatory attributes defined in TalentLMS.
Any additional attributes sent by Salesforce, including attributes used for custom user fields, are also displayed in this section. These attributes do not have a green checkmark unless they correspond to one of the mandatory TalentLMS attributes. Verify that their values are correct.
If all four mandatory attributes have a green checkmark and the displayed values are correct, the SSO configuration has been successfully validated.