<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Salesforce SSO Error: The Audience in the Assertion Did Not Match the Allowed Audiences

Single Sign-On
Okta Classic Engine
Okta Identity Engine

Overview

A Salesforce Single Sign-On (SSO) error occurs when the Entity ID does not match exactly between Okta and Salesforce or when a sandbox environment uses the incorrect production URL. Correcting the Entity ID in the Salesforce settings and ensuring the Okta domain is configured properly resolves the issue.

 

After setting up Salesforce with Secure Assertion Markup Language (SAML), the login flow fails with the following error visible on the Salesforce landing page:

 

The audience in the assertion did not match the allowed audiences.

 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Salesforce
  • Secure Assertion Markup Language (SAML)

Cause

The Entity ID in Salesforce is case-sensitive and must match exactly. Additionally, when configuring a sandbox environment, the Entity ID requires the production URL rather than the sandbox URL.

Solution

How is the Salesforce Entity ID mismatch resolved?

 

Update the Entity ID in the Salesforce settings and verify the Okta domain configuration to resolve the mismatch.

  • Edit the Entity ID in the Salesforce settings to ensure an exact match between Okta and Salesforce, including uppercase and lowercase letters.
  • Verify the Entity ID uses the production URL when configuring a sandbox environment (for example, use the Production URL ("https://mydomain.my.salesforce.com") instead of the Sandbox URL ("https://mydomain--mysandbox.sandbox.my.salesforce.com").
  • Verify the domain in Okta is set to the base domain (e.g., mydomain) and does not include the sandbox suffixes (for example, mydomain--mysandbox or mydomain--mysandbox.sandbox).
Loading
Okta Salesforce SSO Error: The Audience in the Assertion Did Not Match the Allowed Audiences | Okta Support