Loading

SSO (Single Sign-On) SAML Settings Behavior During Sandbox Refresh — What Is Copied and What Changes

Data pubblicazione: Aug 4, 2026
Descrizione

When a Salesforce sandbox is refreshed from a production environment, the Single Sign-On (SSO) configuration using SAML (Security Assertion Markup Language) is partially carried over to the refreshed sandbox — but not fully. Specifically, SAML settings are automatically disabled in the sandbox after a refresh because the Recipient URL is updated to match the new sandbox URL assigned by Salesforce.


If your production org uses SSO, users will not be able to log into the refreshed sandbox via SSO immediately after the refresh. The SAML settings must be reconfigured before SSO access is restored in the sandbox.
This article explains what SSO settings are copied during a sandbox refresh, what changes automatically, and what steps are required to re-enable SSO access in the refreshed sandbox.

Risoluzione

What Happens to SSO Settings During a Sandbox Refresh

When a sandbox is refreshed, the following behavior applies to SSO (SAML) settings:

  • What is copied: All SSO configuration options from production are mirrored into the sandbox, including certificates, Identity Provider (IDP) settings, and other SAML configuration fields.
  • What changes: The Recipient URL is automatically updated by Salesforce to match the new sandbox URL (Sandbox My Domain URL). Because the Recipient URL changes, the SAML settings are disabled in the sandbox after the refresh.
  • Org ID: The sandbox org ID changes with every refresh. Because the org ID is part of the SSO configuration, this change invalidates the SSO settings and requires reconfiguration.

 

Important Considerations After a Sandbox Refresh

  • If SSO is enabled in production with a custom profile that has the SSO permission enabled, login to the sandbox may be blocked immediately after the refresh for those users. Users with standard profiles are not affected by this limitation.
  • After the Recipient URL is updated in the sandbox, you must download the sandbox SAML metadata and provide it to your Identity Provider (IDP). The IDP must update its configuration to reflect the new sandbox URL and org ID.
  • After the sandbox refresh, a system administrator may need to contact Salesforce Support to request a password reset email, which allows them to bypass the security question prompt and set up a new password to access the sandbox directly (without SSO).

 

Step 1: Re-Enable SAML in the Refreshed Sandbox

  1. Log into the sandbox org as a system administrator (using username/password, not SSO).
  2. Navigate to Setup.
  3. In Lightning Experience: Setup | Identity | Single Sign-On Settings. In Salesforce Classic: Setup | Administer | Security Controls | Single Sign-On Settings.
  4. Click Edit, then check the SAML Enabled checkbox.
  5. Click Save.
  6. Update the Recipient URL to match the sandbox URL and reconfigure any additional IDP settings as needed.

 

Step 2 (Alternative): Accessing the Sandbox When Locked Out

If the administrator cannot log into the refreshed sandbox via SSO, use one of the following methods to regain access:

  • Option A: Log in directly using local credentials                                                                                              Navigate to (https://test.salesforce.com) (or the Sandbox My Domain URL). Log in using your Sandbox username (user@domain.com.sandboxname) and the password that was active in Production at the time of the refresh.
  • Option B: Reset via another Sandbox Admin                                                                                                                If another administrator already has direct access to the Sandbox, have them navigate to Setup | Users inside the Sandbox, remove the .invalid suffix from your email address, save, and click Reset Password. 
  • Option C: Contact Salesforce Support                                                                                                                            If all system administrators are completely locked out of the Sandbox, open a case with Salesforce Support from your Production org. Provide the Sandbox Org ID and request a password reset email for the affected Sandbox administrator.
Numero articolo Knowledge

000385851

 
Caricamento
Salesforce Help | Article