Salesforce ArchitectureArchitect (Hardest)identitymulti-orgsso
Design enterprise identity federation architecture across twelve Salesforce orgs
Real World Scenario
Employee accesses 4 of 12 Salesforce orgs; duplicate accounts and password fatigue drive SSO federation project.
Expected Answer
• Single IdP Azure AD Okta SAML all orgs
• SCIM provisioning automate user lifecycle all orgs
• FederationIdentifier consistent key cross-org
• Org access entitlement IdP group mapping
• Integration users excluded separate vault credential
• Experience Cloud external identity separate B2B B2C flows
• Annual access certification all orgs consolidated report
Follow-Up Questions & Answers
Click to expand — each follow-up includes a direct, interview-ready answer
Direct answer: Single IdP Azure AD Okta SAML all orgs Also consider: SCIM provisioning automate user lifecycle all orgs In practice: FederationIdentifier consistent key cross-org Document the decision in an ADR and align with enterprise standards.
Architect Perspective
12 orgs without federation is 12 password problems—SCIM plus SAML enterprise mandatory.