Loading
Salesforce now sends email only from verified domains. Read More
Identify Your Users and Manage Access
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Troubleshoot SAML Assertion Errors

          Troubleshoot SAML Assertion Errors

          Use the SAML Assertion Validator to troubleshoot single sign-on (SSO) login problems and identify errors in SAML assertions sent by your identity provider.

          Required Editions

          Available in: both Salesforce Classic and Lightning Experience

          Federated Authentication is available in: All Editions

          Delegated Authentication is available in: Professional, Enterprise, Performance, Unlimited, Developer, and Database.com Editions

          Authentication Providers are available in: Professional, Enterprise, Performance, Unlimited, and Developer Editions

          User Permissions Needed
          To view the settings: View Setup and Configuration
          To edit the settings:

          Customize Application

          AND

          Modify All Data

          If users have difficulty logging in after you configure Salesforce as a SAML service provider, use the SAML Assertion Validator to find assertion errors.

          Note
          Note Some errors stop the validator from continuing, potentially leaving undetected errors. After you fix initial errors, run the assertion through the validator again to ensure that it hasn’t missed anything.
          1. Obtain a SAML assertion in plain XML, base-64 encoded, or deflated and base-64 encoded format from your identity provider.

            If a user can’t log in to Salesforce, the invalid SAML assertion is automatically entered into the SAML Assertion Validator, if possible. Some errors prevent the assertion from being entered automatically.

          2. From Setup, enter Single Sign-On Settings in the Quick Find box, select Single Sign-On Settings, then click SAML Assertion Validator.
          3. Enter the SAML assertion into the text box, and click Validate.
            Note
            Note If your org has multiple SAML SSO configurations, the validator tries to detect the right one. You can also select a configuration by clicking the dropdown arrow next to Auto detect config.
          4. Share the results of the validation errors with your identity provider.

          The validator only detects errors related to the SAML assertion. To troubleshoot errors unrelated to the assertion, view the login history.

           
          Loading
          Salesforce Help | Article