Suggested answer

An org-wide failure is a configuration or certificate event, and the first question is what changed — on either side.

1. Login History and the error text: signature validation, audience mismatch, and expired assertion each point somewhere different.
2. Certificate expiry. The single most common cause. The identity provider rotated a signing certificate, or the certificate in the Salesforce single sign-on settings expired.
3. My Domain or endpoint changes. If My Domain was changed, or the identity provider's application was reconfigured, the audience and recipient no longer match.
4. Clock drift on the identity provider host, if the failures are intermittent rather than total.
5. The My Domain authentication configuration — someone may have unchecked the single sign-on option, leaving a valid configuration nobody can reach.

Two things I always cover in the same breath. First, a break-glass administrator account that does not depend on single sign-on, held under proper controls, so the org is recoverable. Second, the Setup Audit Trail, which will usually name the change and the person within a minute of looking.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.