Service Providers

Integrations > Security > Outbound SSO > Service Providers

These are the Outbound SSO Service Providers that Medallia Experience Cloud can connect to, and how their connections are configured.

By default, there is provider named Salesforce SP whose application value is Support,Community. This configuration allows users to connect directly to the Knowledge Center from Admin Suite without having to sign in on that site.

Clicking Support redirects the user to the Knowledge Center (the SP), and Medallia is the IdP

Common properties

SP Name
(Required) Name of this service provider to identify this configuration.
Description
Description of this SP configuration for documentation purposes. This text does not appear on the log-in screen.
SSO Protocol
SSO protocol supported by this service provider. At this time only SAML is supported.
Application
The Medallia application this SP serves. When a user clicks a link in Medallia Experience Cloud to connect to the SP, the link is associated with this Application name. Different links can have different application names, and thereby connect to different SPs.
IDP Profile
The Medallia as Identity Provider configuration that is the IdP for this service provider.

SAML SP configuration properties

These properties configure the SAML connection with the SP. Many SPs provide a metadata file that defines these values. Upload that file to automatically define these properties. Alternatively, you can provide them manually.

Metadata file
Metadata file that describes the connection properties needed to communicate with the SP. Uploading the file automatically fills in the values for the required properties in this section.

Initially, this property has a Choose file option to upload the file. Once uploaded, this property changes to Show file with an option to Delete the file and start over.

Issuer Name
Identity of the SP as it appears in the SAML assertion.
NameID Format
Identifies the field — and its format — in the SAML assertion in which the SP expects to find the user account ID.
X.509 Certificate contents

SP's public key to use when encrypting assertions sent by the IdP (Experience Cloud) to the SP.

Restriction: Encrypting the assertion is not supported at this time.
Use HTTP POST binding
(Obsolete) This property is obsolete and will be removed in the future.
Encrypted SAML assertions
Encrypt the SAML assertion sent to the SP.
Restriction: Encrypting the assertion is not supported at this time.
Sign SAML assertions

Experience Cloud will sign the assertion with Medallia's private key, which the SP will verify with Medallia's public key, a copy of which the SP has on record.

Assertion Consumer URL
The SP endpoint (AssertionConsumerURI) where the SAML assertions are posted.