# During Refresh

#### Create Public Group

Create a public group that includes all organization members.

<p class="callout warning">Users who are not part of the public group will not be able to access the sandbox after refresh. This must be completed before sandbox initialization.</p>

#### Verify SSO Configuration

Ensure that Single Sign-On (SSO) is properly configured before the refresh completes. Verify the following:

- SSO metadata is correctly loaded
- Identity provider (IdP) settings are accurate
- Certificate and endpoint configurations are valid

Contact ITS security if these are not upto date.