Skip to main content
The team at my company who manages access to systems would like to vault the Salesforce System Administrator account. I will refer to them as the Security team going forward. In order to ensure the vaulting and check out process works correctly, I shouldn't have access to the password reset links sent to the email address tied to the account. However, the mailbox for our System Administrator account receives many emails from Salesforce that I still need access to.

 

My suggested solution is the following:

  1. After checking out the System Administrator account and completing the necessary work, I notify the Security team that I no longer need access to the account.
  2. The Security team will trigger a password reset email from Salesforce so they can change the password and I no longer know it.
  3. Upon recieving a password reset email in the mailbox tied to the System Administrator, the a mailbox rule will forward the email to a mailbox provided by the Security team so they can change the password.
  4. The mailbox of the System Administrator will then run a mailbox rule that deletes the email from the inbox and also the deleted items folder. This prevents me from being able to use the password reset link.

There is a flaw with my suggested solution: I would have access to disable these mailbox rules and set the password myself, undermining the account vaulting and checkout process.

 

Considering the flaw of my suggested solution, is there a recommended method to handle vaulting the Salesforce System Administator account and the process to checkout the account?
3 Antworten
  1. 20. Dez. 2016, 18:51
    I dont quite understand what you're trying to do. Are you no longer the admin and the "security" team is now? 
0/9000