To protect sensitive resources, you can now configure forced authentication when Salesforce is acting as a SAML identity provider. With forced authentication, users who are already logged in to Salesforce must reenter their credentials when trying to access a third-party service provider. After setting up this feature, you can use the identity provider event log to monitor when users have been logged out due to forced authentication.

Where: This change applies to Salesforce Classic (not available in all orgs) and Lightning Experience in all editions.

How: We provide an example forced authentication SAML request. To configure forced authentication, share this request with your service provider. Your service provider then uses the SAML request to tell Salesforce that the user must reauthenticate. When Salesforce is acting as the identity provider, forced authentication is automatically supported, so no additional setup in your org is required.

Require Users to Reauthenticate When Accessing Service Providers with Single Sign-On (salesforce.com)

Privacy Preference Center