Salesforce plans to migrate global login endpoints from Salesforce-managed first-party (1P) datacenters to Hyperforce. This migration affects customers who use Salesforce Express Connect (SEC) and IP Allowlists Blocking Access to Hyperforce.
Salesforce Express Connect (SEC) is a private network connectivity solution that allows customers to connect to Salesforce over dedicated, non-internet-based links (e.g., AWS Direct Connect, MPLS). Historically, SEC customers have routed traffic through global login endpoints (e.g., login.salesforce.com, test.salesforce.com) for authentication and login flows.
Salesforce is making Global Login infrastructure changes as part of its ongoing evolution to Hyperforce. These changes affect how global endpoints are resolved for customers using private network paths (SEC).
Core Problem: SEC customers routing traffic through global login URLs over private/dedicated circuits will lose connectivity once the global endpoints migrate to Hyperforce infrastructure — unless they transition to My Domain URLs, or adopt AWS Direct Connect (DX).
The test.salesforce.com (TSC, sandbox) endpoints have been permanently migrated to Hyperforce since June 4, 2026.
These global login endpoints begin migrating in July 2026:
To proactively identify customers who might experience an outage during the LSC migration to Hyperforce, the rollout will be a staggered process. Salesforce will perform several short-duration rollouts, followed by rollbacks, to track any possible issues. We will repeat this process until no new critical login-related issues are found, at which point we will permanently keep the login service running exclusively on Hyperforce.
Updated Rollout Plan for LSC (Production):
| LSC Date | Jul 20 | Jul 27 | Aug 3 | Aug 10 | Aug 17 | Aug 20 | Aug 27-28 |
| Duration | 15 mins | 30 mins | 1 hour | 2 hours | 4 hours | 8 hours | Permanent |
| Local time | |||||||
| APAC (Tokyo) | 12:00 PM | 1:00 PM | 2:00 PM | 3:00 PM | 11:00 AM | 10:00 AM | |
| Africa (Johannesburg) | 9:00 AM | 10:00 AM | 11:00 AM | 12:00 PM | 8:00 AM | 7:00 AM | |
| Europe (Paris) | 9:00 AM | 10:00 AM | 11:00 AM | 12:00 PM | 8:00 AM | 7:00 AM | |
| South America (Buenos Aires) | 9:00 AM | 10:00 AM | 11:00 AM | 12:00 PM | 8:00 AM | 7:00 AM | |
| North America (San Francisco) | 9:00 AM | 10:00 AM | 11:00 AM | 12:00 PM | 8:00 AM | 7:00 AM | |
Note:
All times and durations are targets. Migration can take up to 5 minutes for execution and up to 5 minutes for cascading DNS TTL expiration.
This article describes proactive measures you can take to maintain uninterrupted access through the transition. After login traffic moves from Salesforce first-party infrastructure to Hyperforce, requests routed exclusively via SEC to these endpoints will not reach Hyperforce, causing associated functions to fail unless you take preemptive actions. This issue affects all login services that are moving to Hyperforce, starting with LSC and TSC.
As an SEC customer, you can determine if global login endpoints are in use by reviewing the Login URL field in your Salesforce org's Login History. As shown in the example, the login.salesforce.com URL indicates global login. After the endpoints move to Hyperforce, they may no longer work for you. In contrast, a My Domain URL, *.my.salesforce.com, connects directly to your instance in first-party infrastructure and isn’t affected by the LSC/TSC Hyperforce migration.
|
Username |
Login Time |
Source IP |
Location |
Login Type |
Status |
Browser |
Platform |
Application |
Login URL |
|
admin@gs0.dev |
9/16/2025, 10:40:54 AM PDT |
Application |
Success |
Chrome 139 |
Mac OSX |
Browser |
login.salesforce.com | ||
|
admin@gs0.dev |
9/16/2025, 10:40:13 AM PDT |
Application |
Success |
Chrome 139 |
Mac OSX |
Browser |
sp0-dev-ed.my.salesforce.com |
Note:
This document is for informational purposes only, and is not part of any legal or otherwise binding agreement. The policies and practices described in this document are subject to change at Salesforce's sole discretion. All dates are subject to change.
First, ask your Salesforce Express Connect service provider whether they can resolve the global login changes to maintain uninterrupted connectivity, such as switching to AWS Direct Connect. If they can’t, to maintain uninterrupted connectivity, you must implement at least one of these three mitigation options by end of June 2026. If you don’t implement one of these options, you will lose access to the global endpoints, and login and authentication services using the global URLs will fail.
If you have already implemented any of these solutions, you don’t need to take any further action.
Hyperforce is Salesforce’s premiere infrastructure, delivering outstanding security, reliability, and availability to customers’ orgs.
Upgrading to Hyperforce and implementing AWS DX is a long-term solution for direct connectivity to Salesforce. Contact your account team to request a Hyperforce upgrade at any time.
Learn more about Hyperforce in these resources.
To avoid impact on login services and continue using SEC, you can transition all use of login.salesforce.com and test.salesforce.com to your org’s My Domain URL. My Domain is available for all Salesforce orgs. To find the URL, from Setup, in the Quick Find box, enter My Domain, and then select My Domain Settings.
Note: If you are using internal or external applications to integrate with Salesforce that have hard-coded login.salesforce.com URLs, update these apps to use My Domain.
To identify where MyDomain is not yet in use, follow these steps:
My Domain provides a number of benefits for customers. It offers improved performance and security while remaining compatible with a wide range of login functions.
Most login and SSO functions are compatible with My Domain. We recommend that customers verify if they are using any of the following with login.salesforce.com (LSC) or test.salesforce.com (TSC) and switch to My Domain where possible.
While My Domain offers many benefits, you might encounter some of the challenges listed above when you transition to it. We recommend that you start your analysis and migration work as soon as you can. If you find any blockers, implement AWS DX to unblock access.
AWS Direct Connect (DX) is the direct connectivity solution for Hyperforce. To maintain direct access to Salesforce and related services, add AWS Direct Connect to your network before the login traffic transition begins.
AWS Direct Connect (DX) is a dedicated, private network connection service provided by Amazon Web Services. It allows organizations to establish a private, high-bandwidth, low-latency link between their on-premises data center (or corporate network) and AWS infrastructure — completely bypassing the public internet.
Salesforce's Hyperforce platform is built on public cloud infrastructure (AWS). When Salesforce migrates global login endpoints to Hyperforce, the underlying network paths change. Traditional SEC routes that worked on legacy Salesforce infrastructure may not resolve correctly to the new Hyperforce-hosted global IPs.
AWS Direct Connect solves this by providing a dedicated private Virtual Interface (VIF) that connects directly to the AWS network backbone — where Hyperforce runs — ensuring that customers' private connectivity remains intact even after the migration.
We recommend this option if you require direct connectivity. This approach retains existing functionality and avoids the need for application-level changes. Adding AWS DX now prepares your org for an eventual upgrade to Hyperforce.
As we migrate global login endpoints, it's important to be aware of the functionalities that require access, so that you can review their behavior and test your solution. If you don’t take any action, these functions could fail.
login.salesforce.com (LSC) or test.salesforce.com (TSC). As an alternative, you can Define an Authentication Provider and switch to a My Domain URL for SSO requests.login.salesforce.com (LSC) or test.salesforce.com (TSC) for login and OAuth integrations will likely be affected. This includes integrations such as Canvas, Mobile, MailApp, Package Install, and Lightning and Image servlets.login.salesforce.com or test.salesforce.com.
Q: What is the Hyperforce LSC/TSC cutover?
A: The cutover is a deployment process where regional web traffic for login.salesforce.com (LSC) and test.salesforce.com (TSC) is rerouted from our first-party data centers over to the Hyperforce infrastructure.
Q: Will this deployment impact my ability to log in?
A: This migration is designed to ensure that user logins remain fully functional with no downtime. Immediately following the regional cutovers, our teams perform a high-priority, 10-minute system verification to guarantee that traffic is being routed securely and correctly to Hyperforce.
Q: What regions are included in this update?
A: This routing update is a global initiative. Deployments and subsequent performance verifications are conducted across regions worldwide, including North America, South America, Africa, Europe, and Asia-Pacific.
Q: How does Salesforce verify that logins are working properly after the update?
A: During the 10-minute post-deployment window, our engineering teams conduct targeted sanity checks, which include: Verifying that login pages load without errors across standard and custom domain instances. Validating connections by evaluating browser request headers, IPs, and TLS encryption ciphers. Monitoring internal login metrics for consistent availability, request rates, and load-balancing stability. Running automated synthetic tests to simulate login attempts from multiple global locations to ensure 100% availability.
Q: Will I notice any performance changes when logging in?
A: You may experience enhanced performance depending on your location. For example, during post-deployment testing in the Asia-Pacific region, we noted significant improvements in latency for users connecting from Sydney. Overall, the global login volume and reliability remain stable and consistent.
Q: I'm on 1P — do I need to take action before July 20?
A: It depends on whether you're using MyDomain.
The SEC network doesn’t reach Hyperforce directly. MyDomain is the best path. Any SEC customer still logging in via a global non-MyDomain URL will be impacted when login.salesforce.com moves to Hyperforce starting July 20, 2026.
*Note: While using MyDomain means that you don’t have to take action before July 20, in the long term, SEC is end-of-life because all orgs are moving to Hyperforce. When your org migrates to Hyperforce, app traffic tries to go via SEC, SEC can't reach AWS, and your Salesforce integration breaks entirely. See Set Up AWS Direct Connect (DX) for Hyperforce.
Q: Which IP ranges do I need to allow for Hyperforce?
A: Salesforce publishes its current Hyperforce IP ranges in machine-readable format at: https://ip-ranges.salesforce.com/ip-ranges.json. This is the authoritative, up-to-date source. Pull from this file — not from static lists in help articles — because Salesforce is actively migrating to IPAM (centralized IP management), and IP blocks will change over time.
For AWS Direct Connect customers: The DX setup knowledge article contains an additional table with short-term IP addresses for the Salesforce Edge transition. These IP addresses will be removed after the Edge CDN completes its IPAM migration.
Q: What is Salesforce Edge Network, and how do I set it up?
A: Salesforce Edge is a content delivery network (CDN) that helps deliver an enhanced network experience, including improved performance and security, such as advanced application security protections. With Edge and AWS DX, your traffic is routed through DX to your target AWS region, then to the nearest available Edge Point of Presence (PoP), and then to your Salesforce organization.
If you're on MyDomain, your org is already routed through Edge for login and page traffic.
Q: My CRMA/Insights batch jobs failed during TSC — is this expected?
A: Some customer organizations configured with more restrictive IP allowlisting than published guidance may experience CRMA/Insights job failures when the source IPs from Salesforce shift. Make sure to allowlist the Hyperforce IP ranges. See Hyperforce IPs to Allow.
Q: My SSO/OAuth flow broke — how do I update my IdP config?
A: Ensure that you use MyDomain, and log in using Oauth 2.0. See Migrate from OAuth Username-Password to Client Credentials Flow.
Q: What happens if I haven't moved to MyDomain by Jul 20?
A: After July 20, login.salesforce.com will be served by Hyperforce. If your org is not on MyDomain, your login and OAuth flows may break or degrade, depending on how your org and network are configured.
Specifically:
What to do now:
Exceptions to the July 20 deadline are not being granted. If you have a critical blocker, contact your Salesforce account team immediately.
Q: We would like to avoid using AWS; what is your recommendation?
A: To avoid using AWS, stop using login.salesforce.com and switch to MyDomain. MyDomain is hosted on the same infrastructure that your org lives on, and the MyDomain login flow goes directly to your org’s instance without touching Hyperforce infrastructure, which runs on AWS.
005167236

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.