Skip to main content

We use Azure SSO in our production org. Since our full and partial sandboxes contain PII data as well, we need to start using SSO with these sandboxes as well. However, our bank email address is used for SSO and we are having difficulty setting up the Azure SSO to match on email addresses appended with the sandbox name. Has anyone had to deal with this and what was your solution if you don't mind sharing.    Also, we would like to also prevent logins to these sandboxes using SSO if the email address field shows a value still appended with .invalid. Any thoughts concerning this?    Thanks for any help provided.     

2 respostas
  1. Eric Burté (DEVOTEAM) Forum Ambassador
    30 de mai. de 2025, 21:18

    Hello @Samuel Clement, for your first question, I have already made the job by using a SSO setup with Federation identifier on Salesforce side, and ask IdP solution admin to configure an append on its side according to the user group configured (one for Integration, one for UAT, one for PROD). 

    For your second question, there is no way to prevent a user from trying to log in...  The login attempt will just failed and be logged this way in the user's login history. 

    Eric

0/9000