Loading

Resolve Login, Custom Domain, and SSO Errors in the Salesforce Mobile App

Date de publication: Sep 9, 2026
Description

Use this guide to diagnose and resolve specific login failures in the Salesforce Mobile App. Because mobile authentication behaves differently than desktop web browsers, issues are typically caused by mobile-specific OS settings, network routing, or backend Administrator configurations.

Résolution

Before beginning these troubleshooting steps, verify that your device model and operating system meet the current minimum Requirements for the Salesforce Mobile App.

1. Verify Your Device's Internet Access

Before checking app configurations, rule out basic network instability.

  • Check your cellular signal strength and Wi-Fi connection.

  • If the signal is weak, toggle Wi-Fi off and back on.

  • If both cellular and Wi-Fi are weak or unstable, wait until you can connect to a stronger network.

2. Review Your Salesforce Login Server & Custom Domain

The Salesforce Mobile App must point to the correct login server. If you use a Sandbox or a Custom Domain, the default Production server will not accept your credentials.

  1. On the mobile app login screen, tap the Gear icon (top right) to view the list of servers.

  2. Note the login URL you normally use on your desktop, and match it to the correct mobile server:

 

Desktop Login URL

Server to Select in Mobile App

Production
Sandbox
Add a Custom Connection using that URL
 
Note: The custom URL must end with my.salesforce.com. Using lightning.force.com is not supported and may cause errors such as "Grant Type not supported."

Known Issue: iOS Smart Punctuation (The Em Dash Bug)
Symptom: iOS users repeatedly fail to log into Sandboxes, even when typing the correct custom URL.
Root Cause: Sandbox URLs contain a double hyphen (--). Apple’s default iOS "Smart Punctuation" feature automatically converts double hyphens into a single em dash (—). This silently corrupts the URL in the mobile app.
Resolution: Copy the correct URL and paste it directly into the mobile app, OR temporarily disable the OS feature by navigating to your iPhone/iPad Settings > General > Keyboard and toggling off Smart Punctuation.

Experience Site (Community) Note:

Include the login URL for your Experience Site to connect as a Partner user. See Differences between Salesforce App and the Full Site for Communities.

 

3. SSO (Single Sign-On) Authentication Failures

If your organization uses a third-party Identity Provider (IdP) like Okta, Ping, or Microsoft Entra ID, mobile SSO failures are usually tied to network routing or stale cache data.

(For a deep dive into resolving specific SAML errors, IdP portal routing, or certificate issues, refer to our dedicated guide: Troubleshoot Single Sign-On for the Salesforce Mobile App).

  • Intranet-Only IdPs: If your SSO provider is hosted on an internal corporate network, it cannot be reached over standard cellular networks. You must activate your Mobile VPN (e.g., Cisco AnyConnect) before opening the Salesforce app.

  • Clear Mobile SSO Cache: If you are stuck in a login loop or seeing an old SSO error, clear the mobile app cache to force a fresh routing session to your IdP.

  • Resolving New Device MFA Blocks: To allow a user with a new phone to log in, go to Setup > Users, select the affected user, and click Disconnect next to App Registration: Salesforce Authenticator (or One-Time Password Authenticator). The user will be prompted to register their new device upon their next login.

  • Authentication Services for SSO: If users are bypassing SSO and receiving standard password errors, verify your My Domain settings. Under Authentication Configuration, ensure your SSO provider is actively selected as an Authentication Service.

4. Account Lockouts & MFA Device Changes

  • The 10-Attempt Lockout: For security, Salesforce accounts temporarily lock after a set number of invalid login attempts (usually 3, 5, or 10). Entering an invalid Multi-Factor Authentication (MFA) token also counts as an invalid attempt. You must wait for the lockout period to expire (typically 15 to 60 minutes) or ask your Salesforce Administrator to unlock your account.

  • Upgraded/New Mobile Devices (MFA Transfer): If you recently upgraded to a new phone, your previous device is still mathematically bound to your Salesforce account. You cannot log in until your Administrator severs the old connection. Reach out to your Admin to disconnect your old authenticator.

5. Passkey Support & MDM Routing Configuration

Passkey Support Status: FIDO2 Passkeys (such as FaceID/TouchID tied to WebAuthn) are fully supported for the Salesforce Mobile App, but they will fail if the org is using the default mobile app configuration.

The standard Salesforce mobile app webview cannot natively prompt OS-level biometrics or pass device certificates used by Mobile Device Management (MDM) tools like Microsoft Intune or Workspace ONE.

Required Admin Fix for Passkeys & MDM: To support Passkeys or Conditional Access, you must force the mobile app to use the device's native browser for authentication.

  1. Go to Setup > My Domain.

  2. Scroll down to Authentication Configuration and click Edit.

  3. Check the boxes for Use the native browser for user authentication on iOS and Use the native browser for user authentication on Android.

  4. Click Save.

6. Verify API Permissions & IP Range Blocks

If an end-user’s credentials and URLs are perfectly correct, but they receive an immediate error upon clicking "Log In," verify their profile configurations.

  • API Enabled Permission: The Salesforce Mobile App requires API access to interact with the database. Navigate to Setup > Profiles, select the user's profile, and ensure the API Enabled checkbox is checked under Administrative Permissions.

  • Login IP Ranges: Check the user’s profile for restricted Login IP Ranges. If a user is attempting to log in over a cellular network, their carrier IP address will fall outside internal corporate IP ranges, which will block access. They must connect to a permitted Wi-Fi network or use a corporate Mobile VPN.

Note for MDM/SSO Users: If your organization uses Mobile Device Management (MDM) or Conditional Access, test enabling "Use the native browser for user authentication (for iOS/Android)" in your org's My Domain settings. This allows the authentication flow to bypass the app's web view and successfully verify device certificates.

Numéro d’article de la base de connaissances

000386369

 
Chargement
Salesforce Help | Article