---
title: Configure direct Salesforce sign-on using PingFederate (SP-initiated sign-on) plus single logout (SLO)
description: You must first enable IdP-initiated sign-on.
component: configuration_guides
page_id: configuration_guides:salesforce:config_signon_slo_salesforce_pf
canonical_url: https://docs.pingidentity.com/configuration_guides/salesforce/config_signon_slo_salesforce_pf.html
revdate: May 15, 2024
section_ids:
  before-you-begin: Before you begin
  enable-pingfederate-authentication-in-salesforce: Enable PingFederate authentication in Salesforce
  test-the-pingfederate-sp-initiated-sso-integration: Test the PingFederate SP-initiated SSO integration
---

# Configure direct Salesforce sign-on using PingFederate (SP-initiated sign-on) plus single logout (SLO)

## Before you begin

* You must first enable IdP-initiated sign-on.

## Enable PingFederate authentication in Salesforce

1. Sign on to your Salesforce domain as an administrator.

2. Click the **Gear** icon, then go to **Setup → Company Settings → My Domain**.

   ![Screen capture of the Salesforce Settings menu with the My Domain tab highlighted.](_images/huz1619218618296.png)

3. Make a note of your domain name, such as `https://your-company.my.salesforce.com`.

4. In the **Authentication Configuration** section, click **Edit**.

   ![Screen capture of the Salesforce Authentication Configuration page with the Edit button highlighted in red.](_images/zvc1619218660632.png)

5. In the **Authentication Service** list, select **YourPingFederate**. Click **Save**.

   ![Screen capture of the Salesforce Authentication Configuration page with the Save and YourPingFederate check box highlighted in red.](_images/abf1619218701705.png)

   |   |                                                                                              |
   | - | -------------------------------------------------------------------------------------------- |
   |   | The "YourPingFederate" entry was created as a result of the IdP-initiated login tasks above. |

   Configuration is complete.

Salesforce will now redirect to PingFederate for authentication of all new sessions.

You should also select the **Login Form** check box during the testing phase in case of authentication issues. Testers will be offered the option of the standard Salesforce login form or PingFederate authentication. After you've successfully tested authentication against PingFederate, you can clear the **Login Form** check box so that authentication automatically defaults to PingFederate.

## Test the PingFederate SP-initiated SSO integration

1. Go to your Salesforce domain.

   |   |                                                                                                                                                                                                                                                                                  |
   | - | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   |   | If the **Login Form** check box is still selected, the Salesforce sign on screen still displays, and you're offered a choice of Salesforce sign on or PingFederate sign on, select **PingFederate**.If you've cleared the **Login Form** check box, you're not offered a choice. |

2. When you are redirected to PingFederate, enter your PingFederate username and password.

   After successful authentication, you're redirected back to Salesforce.

   ![Screen capture of the Salesforce home page.](_images/dra1619218741821.png)
