All articlesArticle

Show Unique SSO Options in a Community Site Based on User Email Domain

Modern Salesforce Community sites often host users from multiple groups—customers, internal employees, and various partners. Each group may require a unique authentication process, but how do you ensure users only see the Single Sign-On (SSO) options relevant to them, while keeping other login methods hidden?

This post explores a customizable solution implemented with a Lightning Web Component (LWC), allowing you to dynamically display or hide SSO and password login options based on the user’s email address input. This approach ensures a streamlined, private, and user-tailored login experience on your Salesforce portal.

The Challenge: Unique Authentication for Distinct User Groups

Imagine you want regular customers to log in with a simple username and password, while employees and partners must use SSO. Further, suppose you want specific SSO providers to be available exclusively to specific partners, so that no user can see login options intended for another group. The default Salesforce login page does not support this granularity out of the box.

The Solution: Dynamic Login Option Rendering with Lightning Web Components

A Lightning Web Component was developed to solve this challenge. Here’s an overview of the end-user experience:

  • Customer Users:
  • When a customer enters their email address (e.g., user@customer.com), the page detects that they should log in with a password. The password field appears, and there is no SSO option visible.
  • Partner or Employee Users:
  • As a partner or employee begins typing their email (for example, containing the word private or matching a company domain), the component dynamically hides the password field and displays only the relevant SSO button. Other SSO providers remain hidden from view.
  • Multiple SSO Providers:
  • You can support multiple SSO providers (e.g., “Company A SSO”, “Company B SSO”). Each provider’s login button only appears for users with the matching email domain, so users are never aware of alternate authentication methods.

This privacy-focused approach ensures organization-specific login flows remain confidential and relevant to each user.

A Technical Look: Lightning Web Component and Apex Logic

Lightning Web Component (LWC)

The custom LWC is added to your portal’s login page. It listens as users type their email address:

  • Triggers when certain keywords or domains are detected in the email.
  • Shows or hides the password field and toggles the appropriate SSO login button.

Apex Backend

An Apex class complements the LWC, handling authentication logic based on whether the user is logging in with a password or via SSO.

Key Points

  • The LWC is flexible and can be adapted for any number of SSO providers and user groups.
  • You must have a portal and SSO configurations set up in your Salesforce org.
  • The amount of code required is minimal, but the impact on user experience and security is significant.

Practical Benefits

  • User Experience: Users only see the login methods relevant to their organization or status.
  • Security and Privacy: Each login option is private to the intended group.
  • Customization: Easily adaptable to future changes or additional user groups.

Get Help Implementing This Solution

  • This approach can unlock secure, elegant authentication flows on your Salesforce Community site. If you’d like more detailed guidance, code samples, or advice specific to your organization, our team at SOLVD.cloud is here to help.