When a user cannot log into Salesforce using Single Sign-On (SSO), the failure is typically caused by one or more of the following: the user's profile does not have SSO enabled, the Federation ID in Salesforce does not match the identifier sent by the Identity Provider (IdP), the SAML (Security Assertion Markup Language) assertion contains errors or incorrect attributes, or the IdP certificate uploaded to Salesforce is expired or invalid. This article walks through each of these areas to identify and resolve the issue.
Follow the steps below to troubleshoot SSO login failures in Salesforce. Work through each section in order — most issues are resolved in the first two sections.
Go to Setup, search for Users in the Quick Find box, and open the affected user's record.
Confirm the user's Profile has Single Sign-On enabled. Navigate to Setup > Profiles, open the profile, and verify the Is Single Sign-On Enabled checkbox is checked under Administrative Permissions.
Verify the user's Federation ID in Salesforce exactly matches the unique identifier their Identity Provider (IdP) sends during authentication. A difference in case or whitespace will cause login to fail.
In Setup, search for Single Sign-On Settings and open it. Confirm the Identity Provider Login URL and Salesforce Login URL match your IdP's configuration.
Confirm the IdP certificate uploaded to Salesforce is valid and not expired. If expired, upload the renewed certificate from your IdP and save the SSO configuration.
Examine the SAML assertion sent by the IdP during the failed login attempt for errors or incorrect attributes. Use a SAML tracing tool such as the SAML Tracer browser extension to capture the assertion.
Check your Identity Provider's logs for errors related to the SSO attempt, such as attribute mapping failures or certificate signature mismatches.
Test the SSO connection from the Identity Provider side to confirm it redirects correctly to Salesforce.
Note: This step temporarily changes the user's login method — inform the user before proceeding. On the user's profile, temporarily uncheck Is Single Sign-On Enabled and ask the user to log in with their Salesforce username and password. If login succeeds, the issue is isolated to the SSO configuration. Re-enable the setting after testing.
If all steps above have been completed and the issue persists, contact Salesforce Support with detailed logs from both Salesforce Login History and your Identity Provider.
005389422

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.