Loading

Prepare for Global Login Changes — Salesforce Express Connect (SEC) Users and IP Allowlists Blocking Access to Hyperforce

Publiceringsdatum: Jul 21, 2026
Beskrivning

Salesforce plans to migrate global login endpoints from Salesforce-managed first-party (1P) datacenters to Hyperforce. This migration affects customers who use Salesforce Express Connect (SEC) and IP Allowlists Blocking Access to Hyperforce.

Overview & Summary

Salesforce Express Connect (SEC) is a private network connectivity solution that allows customers to connect to Salesforce over dedicated, non-internet-based links (e.g., AWS Direct Connect, MPLS). Historically, SEC customers have routed traffic through global login endpoints (e.g., login.salesforce.com, test.salesforce.com) for authentication and login flows.
Salesforce is making Global Login infrastructure changes as part of its ongoing evolution to Hyperforce. These changes affect how global endpoints are resolved for customers using private network paths (SEC).

Core Problem: SEC customers routing traffic through global login URLs over private/dedicated circuits will lose connectivity once the global endpoints migrate to Hyperforce infrastructure — unless they transition to My Domain URLs, or adopt AWS Direct Connect (DX).
  • Impacted: First-Party customers who have Salesforce Express Connect (SEC), as well as customers whose network has a firewall policy, IP route, or IP Allowlist that restricts access to Hyperforce public internet ranges.
  • Not impacted: Customers already on Hyperforce, customers who use domain allowlists, or customers who do not restrict access to the Internet.

The test.salesforce.com (TSC, sandbox) endpoints have been permanently migrated to Hyperforce since June 4, 2026.

These global login endpoints begin migrating in July 2026:

  • login.salesforce.com (LSC)
  • login.database.com
  • webto.salesforce.com

To proactively identify customers who might experience an outage during the LSC migration to Hyperforce, the rollout will be a staggered process. Salesforce will perform several short-duration rollouts, followed by rollbacks, to track any possible issues. We will repeat this process until no new critical login-related issues are found, at which point we will permanently keep the login service running exclusively on Hyperforce.

 

Updated Rollout Plan for LSC (Production):

 

LSC DateJul 20Jul 27Aug 3Aug 10Aug 17Aug 20Aug 27-28
Duration15 mins30 mins1 hour2 hours4 hours8 hoursPermanent
Local time
APAC (Tokyo)12:00 PM1:00 PM2:00 PM3:00 PM11:00 AM10:00 AM
Africa (Johannesburg)9:00 AM10:00 AM11:00 AM12:00 PM8:00 AM7:00 AM
Europe (Paris)9:00 AM10:00 AM11:00 AM12:00 PM8:00 AM7:00 AM
South America (Buenos Aires)9:00 AM10:00 AM11:00 AM12:00 PM8:00 AM7:00 AM
North America (San Francisco)9:00 AM10:00 AM11:00 AM12:00 PM8:00 AM7:00 AM

Note
All times and durations are targets. Migration can take up to 5 minutes for execution and up to 5 minutes for cascading DNS TTL expiration. 

This article describes proactive measures you can take to maintain uninterrupted access through the transition. After login traffic moves from Salesforce first-party infrastructure to Hyperforce, requests routed exclusively via SEC to these endpoints will not reach Hyperforce, causing associated functions to fail unless you take preemptive actions. This issue affects all login services that are moving to Hyperforce, starting with LSC and TSC.

  • Proactive Testing
    We recommend testing your connectivity to Hyperforce outside of the scheduled test windows. This allows you to test → make changes → verify readiness at your own pace.
    Use this publicly available Hyperforce URL to test your connectivity:
    Production: login-canary.salesforce.com
    A successful connection will redirect your browser to the existing endpoint. Failures will either time out or return an error.
  • For non-browser or server-based environments, you can test using the following CLI command: curl -v https://login-canary.salesforce.com

As an SEC customer, you can determine if global login endpoints are in use by reviewing the Login URL field in your Salesforce org's Login History. As shown in the example, the login.salesforce.com URL indicates global login. After the endpoints move to Hyperforce, they may no longer work for you. In contrast, a My Domain URL, *.my.salesforce.com, connects directly to your instance in first-party infrastructure and isn’t affected by the LSC/TSC Hyperforce migration.

 

Username

Login Time

Source IP

Location

Login Type

Status

Browser

Platform

Application

Login URL

admin@gs0.dev

9/16/2025, 10:40:54 AM PDT

Salesforce.com IP

Application

Success

Chrome 139

Mac OSX

Browser

login.salesforce.com

admin@gs0.dev

9/16/2025, 10:40:13 AM PDT

Salesforce.com IP

Application

Success

Chrome 139

Mac OSX

Browser

sp0-dev-ed.my.salesforce.com

 

Note: 
This document is for informational purposes only, and is not part of any legal or otherwise binding agreement. The policies and practices described in this document are subject to change at Salesforce's sole discretion. All dates are subject to change.

Lösning

First, ask your Salesforce Express Connect service provider whether they can resolve the global login changes to maintain uninterrupted connectivity, such as switching to AWS Direct Connect. If they can’t, to maintain uninterrupted connectivity, you must implement at least one of these three mitigation options by end of June 2026. If you don’t implement one of these options, you will lose access to the global endpoints, and login and authentication services using the global URLs will fail.

If you have already implemented any of these solutions, you don’t need to take any further action.

Option 1 (recommended): Upgrade to Hyperforce and Implement AWS DX

Hyperforce is Salesforce’s premiere infrastructure, delivering outstanding security, reliability, and availability to customers’ orgs.

 

Upgrading to Hyperforce and implementing AWS DX is a long-term solution for direct connectivity to Salesforce. Contact your account team to request a Hyperforce upgrade at any time.

Learn more about Hyperforce in these resources.

 

Option 2: Transition to My Domain and Discontinue Use of TSC and LSC

To avoid impact on login services and continue using SEC, you can transition all use of login.salesforce.com and test.salesforce.com to your org’s My Domain URL. My Domain is available for all Salesforce orgs. To find the URL, from Setup, in the Quick Find box, enter My Domain, and then select My Domain Settings.

 

Note: If you are using internal or external applications to integrate with Salesforce that have hard-coded login.salesforce.com URLs, update these apps to use My Domain.

 

To identify where MyDomain is not yet in use, follow these steps:

  • Check their login history to download a list of recent login data. Help article.
  • Filter for records where the Login URL is login.salesforce.com.
  • Work with the relevant application or service team to switch to their MyDomain. For SOAP/API applications, this article explains how to do it.

 

My Domain provides a number of benefits for customers. It offers improved performance and security while remaining compatible with a wide range of login functions.

Key Benefits

  • Improved Performance: Direct My Domain connections avoid extra routing, which improves login performance.
  • Enhanced Security: My Domain allows for the application of mTLS authentication and other connection features for stronger security.

Compatible Login and SSO Functions

Most login and SSO functions are compatible with My Domain. We recommend that customers verify if they are using any of the following with login.salesforce.com (LSC) or test.salesforce.com (TSC) and switch to My Domain where possible.

 

While My Domain offers many benefits, you might encounter some of the challenges listed above when you transition to it. We recommend that you start your analysis and migration work as soon as you can. If you find any blockers, implement AWS DX to unblock access.

Option 3: Add AWS Direct Connect (DX) Alongside SEC Before Login Traffic Transition

AWS Direct Connect (DX) is the direct connectivity solution for Hyperforce. To maintain direct access to Salesforce and related services, add AWS Direct Connect to your network before the login traffic transition begins.

AWS Direct Connect (DX) is a dedicated, private network connection service provided by Amazon Web Services. It allows organizations to establish a private, high-bandwidth, low-latency link between their on-premises data center (or corporate network) and AWS infrastructure — completely bypassing the public internet.

Why Does It Matter for Salesforce Hyperforce?

Salesforce's Hyperforce platform is built on public cloud infrastructure (AWS). When Salesforce migrates global login endpoints to Hyperforce, the underlying network paths change. Traditional SEC routes that worked on legacy Salesforce infrastructure may not resolve correctly to the new Hyperforce-hosted global IPs.
AWS Direct Connect solves this by providing a dedicated private Virtual Interface (VIF) that connects directly to the AWS network backbone — where Hyperforce runs — ensuring that customers' private connectivity remains intact even after the migration.

We recommend this option if you require direct connectivity. This approach retains existing functionality and avoids the need for application-level changes. Adding AWS DX now prepares your org for an eventual upgrade to Hyperforce.

Benefits

  • Works for all global endpoints migrating to Hyperforce, not just login.
  • Prevents disruptions from future org migrations to Hyperforce.
  • Proven to work for other SEC customers using both SEC and AWS DX.

Reference

 

Functionality Related to Global Login Endpoint Access

As we migrate global login endpoints, it's important to be aware of the functionalities that require access, so that you can review their behavior and test your solution. If you don’t take any action, these functions could fail.

  • Global Auth Providers: Global authentication providers for services such as Google, Facebook, and Microsoft use a global callback URL that requires login.salesforce.com (LSC) or test.salesforce.com (TSC). As an alternative, you can Define an Authentication Provider and switch to a My Domain URL for SSO requests.
  • Login Hints: This feature requires global access to LSC/TSC to function. However, it’s not a login blocker and can be disabled if necessary.
  • Custom Apps: Custom apps that use login.salesforce.com (LSC) or test.salesforce.com (TSC) for login and OAuth integrations will likely be affected. This includes integrations such as Canvas, Mobile, MailApp, Package Install, and Lightning and Image servlets.
  • Undetected Clients: You might not be able to identify every client using the global endpoints. Prioritizing the adoption of AWS Direct Connect will help prevent unexpected connectivity issues.
  • Application Updates: To make sure your integrations keep working and to retain existing functionality, you may need to update or reconfigure applications installed in your Salesforce organization(s) to use My Domain URLs instead of login.salesforce.com or test.salesforce.com.

 

FAQ: Hyperforce Login Routing Update

Q: What is the Hyperforce LSC/TSC cutover?
A: The cutover is a deployment process where regional web traffic for login.salesforce.com (LSC) and test.salesforce.com (TSC) is rerouted from our first-party data centers over to the Hyperforce infrastructure.

 

Q: Will this deployment impact my ability to log in?
A: This migration is designed to ensure that user logins remain fully functional with no downtime. Immediately following the regional cutovers, our teams perform a high-priority, 10-minute system verification to guarantee that traffic is being routed securely and correctly to Hyperforce.

 

Q: What regions are included in this update?
A: This routing update is a global initiative. Deployments and subsequent performance verifications are conducted across regions worldwide, including North America, South America, Africa, Europe, and Asia-Pacific.

 

Q: How does Salesforce verify that logins are working properly after the update?
A: During the 10-minute post-deployment window, our engineering teams conduct targeted sanity checks, which include: Verifying that login pages load without errors across standard and custom domain instances. Validating connections by evaluating browser request headers, IPs, and TLS encryption ciphers. Monitoring internal login metrics for consistent availability, request rates, and load-balancing stability. Running automated synthetic tests to simulate login attempts from multiple global locations to ensure 100% availability.

 

Q: Will I notice any performance changes when logging in?
A: You may experience enhanced performance depending on your location. For example, during post-deployment testing in the Asia-Pacific region, we noted significant improvements in latency for users connecting from Sydney. Overall, the global login volume and reliability remain stable and consistent.

 

Q: I'm on 1P — do I need to take action before July 20?
A: It depends on whether you're using MyDomain.

  • If you're using MyDomain for 100% of your org: You don’t need to take action before July 20. The LSC cutover doesn’t affect you.*
  • If you are NOT using MyDomain: Contact your Salesforce account team immediately.

The SEC network doesn’t reach Hyperforce directly. MyDomain is the best path. Any SEC customer still logging in via a global non-MyDomain URL will be impacted when login.salesforce.com moves to Hyperforce starting July 20, 2026.

*Note: While using MyDomain means that you don’t have to take action before July 20, in the long term, SEC is end-of-life because all orgs are moving to Hyperforce. When your org migrates to Hyperforce, app traffic tries to go via SEC, SEC can't reach AWS, and your Salesforce integration breaks entirely. See Set Up AWS Direct Connect (DX) for Hyperforce.

 

Q: Which IP ranges do I need to allow for Hyperforce?
A: Salesforce publishes its current Hyperforce IP ranges in machine-readable format at: https://ip-ranges.salesforce.com/ip-ranges.json. This is the authoritative, up-to-date source. Pull from this file — not from static lists in help articles — because Salesforce is actively migrating to IPAM (centralized IP management), and IP blocks will change over time.

For AWS Direct Connect customers: The DX setup knowledge article contains an additional table with short-term IP addresses for the Salesforce Edge transition. These IP addresses will be removed after the Edge CDN completes its IPAM migration.

 

Q: What is Salesforce Edge Network, and how do I set it up?
A: Salesforce Edge is a content delivery network (CDN) that helps deliver an enhanced network experience, including improved performance and security, such as advanced application security protections. With Edge and AWS DX, your traffic is routed through DX to your target AWS region, then to the nearest available Edge Point of Presence (PoP), and then to your Salesforce organization.

If you're on MyDomain, your org is already routed through Edge for login and page traffic.

 

Q: My CRMA/Insights batch jobs failed during TSC — is this expected?
A: Some customer organizations configured with more restrictive IP allowlisting than published guidance may experience CRMA/Insights job failures when the source IPs from Salesforce shift. Make sure to allowlist the Hyperforce IP ranges. See Hyperforce IPs to Allow.

 

Q: My SSO/OAuth flow broke — how do I update my IdP config?
A: Ensure that you use MyDomain, and log in using Oauth 2.0. See Migrate from OAuth Username-Password to Client Credentials Flow.

 

Q: What happens if I haven't moved to MyDomain by Jul 20?
A: After July 20, login.salesforce.com will be served by Hyperforce. If your org is not on MyDomain, your login and OAuth flows may break or degrade, depending on how your org and network are configured.
Specifically:

  • IP-based network allowlists (firewall rules keyed to old login.salesforce.com IPs) will block the new Edge IP ranges.
  • SEC customers without MyDomain won’t be able to log in because the SEC network doesn’t reach Edge and the legacy endpoint will be unavailable.
  • Connected apps and integrations using login.salesforce.com as the token endpoint may fail.

What to do now:

Exceptions to the July 20 deadline are not being granted. If you have a critical blocker, contact your Salesforce account team immediately.

 

Q: We would like to avoid using AWS; what is your recommendation?
A: To avoid using AWS, stop using login.salesforce.com and switch to MyDomain. MyDomain is hosted on the same infrastructure that your org lives on, and the MyDomain login flow goes directly to your org’s instance without touching Hyperforce infrastructure, which runs on AWS.

Knowledge-artikelnummer

005167236

 
Laddar
Salesforce Help | Article