



| Setting | Status |
|---|---|
| Assertion contains the user's Salesforce username | Enabled |
| Identity is in the NameIdentifier element of the Subject statement | Enabled |
| HTTP POST | Enabled |
| Use Salesforce MFA for this SSO Provider | Enabled |
| Single Logout Enabled | Enabled |
| Use selected request signature method for Single Logout | Enabled |
| Single Logout Request Binding | HTTP POST |
| Field | Value |
|---|---|
| Name | Salesforce |
| Description | Your choice |
| Always Display in UI | ON |
| Field | Value |
|---|---|
| Home URL | https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/<APP_NAME> |
| Valid Redirect URIs | Automatically filled or matches the Salesforce Login URL |
| Valid Post Logout URIs | Automatically filled or matches the Salesforce Logout URL |
| IDP-Initiated SSO URL Name | <APP_NAME> |
| Setting | Value |
|---|---|
| Name ID Format | email |
| Setting | Value |
|---|---|
| Sign Documents | ON |
| Sign Assertions | ON |
| Field | Value |
|---|---|
| Signing Keys Configuration | OFF |
| Encryption Keys Configuration | OFF |
| Field | Value |
|---|---|
| Assertion Consumer Service POST Binding URL | From metadata or login URL |
| Logout Service POST Binding URL | From metadata or logout URL |
| Logout Service Redirect Binding URL | From metadata or logout URL |