Skip to main content

Hi All, 

 

I am trying to set up SSO on a newly refreshed Sandbox which had already had SSO enabled (as does our Prod instance). I refreshed the Sandbox, re-enabled SAML, and configured/confirmed my settings/endpoints to all contain the sandbox URL (which for display purposes, is https://mycompany--testsbname.sandbox.my.salesforce.com). The sandbox URL looks correct in the following places:

 

  • Identity Provider (Issuer/SAML Metadata Discovery Endpoints)
  • Single Sign Setting pages (the three endpoints towards the bottom) 

All other settings (i.e. federated ID, HTTP Redirect, etc. all look correct)

 

But when I try to log in via SSO to the Sandbox, I can get to my company's Idp (OneLogin) page successful, which let's me log in normally (my company's MFA protocol kick in successfully, etc.) but then I get a Salesforce Single Sign in error: "We can't log you in because of an issue with single sign-on. Contact your Salesforce admin for help".

 

  • When I try the Login History the message is: SAML Sfdc Initiated SSO (Type)  Failed: Recipient Mismatched (Status)
  • When I run SAML Assertation Validator on that Single Sign on config, I get the following message (not that the error message is for my production instance, not my Sandbox, which is what I can't seem to find/fix:

 "Incorrect SAML assertion recipient: https://mycompany.my.salesforce.com   We expect one of the Login URLs or OAuth 2.0 Token Endpoints listed on your Single Sign-On Settings page. Warning: Salesforce custom domains and My Domain subdomains must be in lowercase."

 

All the other flags come up green. The error message above seems to be finding my Prod instance URL somewhere, but I can't figure out where I am not looking. Anyone else ever get this error message, or have any ideas on how to tackle this situation? 

 

Any help you can provide would be greatly appreciated. Thank you! #Security #Salesforce Developer #Salesforce Identity #SAML Single Sign On #AwesomeAdmins #SSO

17 answers
  1. Oct 16, 2022, 5:42 AM

    Please check the below points

    1. Please make sure all the URLs are correct in the single sign-on setting. It should be sandbox URLs.

    2. Also please take crt file from the identity provider and upload it again in a single sign-on setting in the issuer.

0/9000