Configuring Salesforce for TaaS
To use Salesforce as an identity provider for TaaS, you must first configure it.
- Sign in to Salesforce and click Setup.
- In the Quick Find text box, enter Identity Provider.
- In the Identity Provider Setup section, click Download Metadata and then provide the downloaded file to Tanium.
- In the Service Providers section, click Service Providers are now created via Connected Apps. Click here.
- In the Basic Information section, enter the required fields.
- In the Web App Settings section, select Enable SAML, enter the following values from your welcome e-mail from Tanium, and then click Save.
Start URL: Console URL
Entity Id: Audience URI (SP Entity ID)
ACS URL: SSO URL
Subject Type: select Username
Name ID Format: select urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
IdP Certificate: select the certificate that corresponds to the previously downloaded metadata file
- In the Custom Attributes section, click New, enter the following values and then click Save.
Attribute key: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
Attribute value: $User.Email
- From the navigation menu, click Manage > Edit Policies.
- In the Profiles section, click Manage Profiles.
- Select the user profiles to assign the enterprise application to any users that you want to have access to TaaS.
You must give access to the user that is listed as the Primary TaaS Admin Username in your welcome e-mail from Tanium. This user is the only user that is created in TaaS during the provisioning process. Additional users can be created in TaaS by this user or other delegated users.
Last updated: 7/30/2021 4:33 PM | Feedback