Loading

Summer '26: Changes to Email Verification and Password Reset Behavior After Sandbox Refresh

Data pubblicazione: Aug 3, 2026
Descrizione
Summer '26: Changes to Email Verification and Generate new password and notify user immediately behaviour After Sandbox Refresh

Beginning with the Summer '26 release, Salesforce introduced a security enhancement that changes how email verification is handled. All email address changes now require a valid session, meaning users must be logged in before they can complete email verification.

This change affects the standard post-sandbox refresh process, where administrators typically remove the ".invalid" from the user email addresses and along with the "Generate new password and notify user immediately".

For more information, refer to the Salesforce release note:
Valid Session Is Always Required for Email Address Changes

 

Previous behaviour (Before Summer '26)

After a sandbox refresh:
The System Administrator removed the .invalid from the user's email address and saved the User record.
Salesforce will send an email verification to the user's email
When the user clicked the "Verify Email" link, the Verify Email Address page was displayed, allowing the user to verify the email address directly.
If the administrator sent a "Generate new password and notify user immediately" along with the email change, the user was able to set the password without first logging in.

 

New behaviour (Summer '26 and Later)
With the Summer '26 release, Salesforce now requires a valid session before a user can verify an email address.

Scenario A – Administrator Removes the .invalid from the email
1. The System Administrator removes the .invalid from the user's email address and saves the User record.
2. Salesforce sends an email verification link.
3. The user clicks the Verify Email link.

Expected behaviour
Instead of being taken to the Verify Email Address page, the user is redirected to the Salesforce login page and this is expected behaviour. The user must first establish a valid session by logging in before the email verification can be completed.

 

 

Risoluzione
Administrator Guidance
Because of this security enhancement, administrators should follow the updated process when managing user email changes.
1. User's Unable to Complete Email Verification
If a user cannot complete email verification, the following workarounds are available:
->Configure Trusted IP Ranges for the organization so the user can establish a valid session.
->Add a phone number to the user's account so an identity verification method is available.

 

2. Users Without a Password
If the user does not have a valid Salesforce password (for example, SSO-only users), the administrator should:
1. Set a password for the user using System.setPassword().
2. Ask the user to log in and establish a valid session.
3. Change the user's email address.
4. The user can then complete email verification successfully.

 

3. SSO Users
If the user authenticates using Single Sign-On (SSO):
1. The user should first log in through the organization's SSO provider.
2. Once the session is established, the user can click the email verification link.
3. The email verification will then complete successfully.

4.Public groups
Before refreshing a sandbox, add key users (such as System Administrators and other critical users) to the designated public group that preserves email addresses during sandbox refreshes. This prevents the .invalid suffix from being appended to their email addresses, reducing the need for manual email updates and email verification after the refresh.

Determine Who Has Sandbox Access

 

 

This behaviour is working as designed and reflects the security enhancements introduced in the Summer '26 release. Administrators should update their post-sandbox refresh procedures accordingly to ensure users can successfully verify their email addresses and complete password-related actions.
Numero articolo Knowledge

005390303

 
Caricamento
Salesforce Help | Article