Skip to main content

#Identity and Access Management4 diskutieren mit

A Salesforce Certified Identity and Access Management Specialist assesses the architecture environment and requirements; and designs sound and scalable technical solutions on the Force.com that meet the Single Sign on (SSO) requirements.

SF is prompting her to authenticate. She has Okta Verify on her account but it is still asking for a SF authentication method. Any idea how to fix it? 

 

#Identity and Access Management  #Salesforce Admin

5 Antworten
  1. 29. Sept., 13:35

    Gotcha - so that is Salesforce's phishing-resistant MFA enforcement, which kicks in for users with the System Administrator profile or any of Modify All Data, View All Data, Customize Application, or Author Apex. Salesforce requires a passkey for those users. Nothing is broken there, that's just part of the rollout.  

     

    The quickest unblock there is just to have her create the passkey.  

     

    Longer term if you want SSO users to skip the passkey, Okta has to perform a phishing-resistant authentication and pass Salesforce the signal identifying which method was used. That would be an Okta app config project. May be worth doing if you have a lot of users hitting this, but that would take some time and the passkey would get her working ASAP.  

     

    Let me know if that makes sense 

    Steve

0/9000

Today I have facing an issue, In my project we have some developer sandboxes. After sandbox refresh action completed, Currently we are unable to verify the email for the non admin users (users whom are not mentioned in the public group which can mentioned during sandbox refresh process). Means, Once sandbox refresh done, We unfreeze the active user and update his original email and that user have received the verification email with verification link. But during clicking the verification link, it's required login to confirm the email address. 

 

But you know, That user doesn't able to login into salesforce because the sandbox just refreshed and user doesn't have the access for the org, We actually ask the user to confirm the email for perform the "password reset" action for that user to enable the access for the org. 

 

So how to by pass this "Login required" behaviour and verify the email link as like previous from the email directly? 

 

Even I have disabled the Permission "

Require identity verification for email address changes" from Identity Verification settings as per Salesforce docs.

 

But still the behaviour is same, So anyone know how to fix/bypass this? 

 

Any help appriciated. 

 

#Salesforce Admin #Sandboxes #Security #Identity and Access Management #Salesforce

 

Thanks, 

Mohanraj S 

 

 

1 Antwort
  1. 22. Sept., 16:06

    We have had luck in resolving this a few ways. 

    • Selecting the 'Generate new password and notify user immediately' checkbox. 
    • Generating a temporary verification code and sending to them. 

    Otherwise you may need to reach out to Salesforce support to get help. There was a bug that says it has been fixed. Users are not able to change and verify their emails in all Orgs after Summer 26 release | Issue Details | Salesforce Help

     

     

    Either way, it also explains other options that may help unstuck your non admins in a Sandbox. 

0/9000

https://sforcemaximizer.com/mastering-salesforce-identity-and-access-management-architect-exam-a-practical-approach-to-exam-preparation-with-my-course/

If you are an admin, developer or architect looking to pass the Salesforce Identity Access Management exam, my blog will provide you the details of a course which I recently authored in Salesforce Ben and help you pass the exam. This is a tough exam due to lack of topic areas where there is not many opportunities to work and get experience on and hope my course helps folks on there journey to CTA!!

@SecurityForce @* Salesforce Administrators * @Admin Tricks@Manufacturing User Group@Higher Ed User Group, Northeast, US@Architect Group, Austin, TX US@Architect Group, Boston, US@Architect Group, Orlando, US@Architect Group, Columbus, OH, US@Architect Group, Los Angeles, US@Architect Group, London, UK@Architect Group, Chennai, IN

 

#Identity and Access Management  #Security

0/9000

Hello, I am preparing for the Identity and Access Management Architect credential.

 

Some time ago, before there was Experience Cloud, I would use either Customer Community and Customer Community Plus licenses for customers logging in to Customer Communities, or Partner Community licenses for partners logging in to Partner Communities.

 

Now we have 2 identity licenses - Identity Only and External Identity:

Salesforce Identity Licenses

 

Identity Only - A license for Salesforce employees (internal users) that want to use Salesforce for logging in to a service outside Salesforce. In this case that would be a user using Salesforce as Identity Provider, but using an external Service Provider app. Yes or no?

 

External Identity - A license for Salesforce consumers of your business, such as customers, prospective customers, patients, partners, and dealers (external users). I don't understand the purpose of this license. As I wrote above, customers and partners have had their own license for some time. Can anyone explain the reasoning behind this?

 

#Identity and Access Management #Technical Architect #Solution Architects #Experience Cloud

10 Antworten
0/9000

User provisioning question - what options do we have to sync user attribute data and provision users in Salesforce from an on-premise system that does not have any prebuilt connectors (like OKTA, AD etc) with no SSO (so no SAML JIT). Is it pretty much limited to using SOAP or REST callouts?

#User Provisioning #Identity and Access Management

1 Antwort
  1. Manoj Nambirajan (Dell Technologies) Forum Ambassador
    11. Juli 2022, 12:15

    yes.. dont see any other option. Could potentially be a webservice call out (soap or rest api) which compares user existence in SFDC while comparing with on-prem system and create user accordingly.

0/9000

I am looking at the documentation for IdP and SP initiated SAML and seem to come across conflicting information if the IdP-initiated SAML supports deep linking. From what I understand, myDomain is required for deep linking in both cases (though generally optional for IdP-initiated SAML) and the IdP must support the RelayState parameter, but then I see other posts saying that only SP-initiated SAML can support deep linking. So which one is correct?

#SAML Single Sign On #Deep Links #IdP Vs SP #Identity and Access Management

1 Antwort
0/9000

Is Salesforce's "OAuth 2.0 User-Agent Flow the same as OAuth Implicit Flow?  Salesforce documentation references OAuth 2.0 User-Agent Flow, but I can't find a reference to this name in any non-Salesforce documentation.  From reading the description of the flow, it *almost* matches what other OAuth-related resources call Implicit Flow or Implicit Grant.  BUT, the Implicit Flow doesn't return a refresh token, while documentation for User-Agent Flow say that a refresh token is returned.  Furthermore, non-Salesforce documents discourage the use of Implicit Flow and instead now recommend Authorization Code with PKCE as an alternative.  So what is this User-Agent flow and how does it map to the flows defined in the OAuth standard?

@Ladies Be Architects #Identity and Access Management #OAuth Flow #Security 

2 Kommentare
  1. 17. Feb. 2020, 13:41

    Hi guys,

    Following up on this:

    We have a requirement to use PKCE for OAuth flows.

    Does Salesforce now support PKCE flows ? and if so where can we get access to docuemntation that illustrates how this can be configured.

    Kind Regards

0/9000

That SSO session was amazing - thanks so much to @Charly Deloitte Prinsloo  for taking us through it. Join us for an in-depth tour around SSO with SAML! We talk about federated authentication, IdP vs SP-initiated flows, SAML parameters and My Domain.

SSO & SAML Study Group - Oct 2018

1 Kommentar
0/9000

@Charly Deloitte Prinsloo  How to access the slide deck of your presentation , Single Sign-On & SAML (Oct. 2018)? Many thanks!

0/9000

Thank you to everybody who took part in @Natalya Murphy's Identity and Access Management study group:

 

John M. Daniel, Madhavi R., Harish Dintakurthi, Winnie Vu, Terry Miller, David Bergerson, Jeff Hunsaker, Svatka Simpson, Luz Paulina Chavez, Brenda Glasser, Amit Jain, Pavithra Vishwanath, Clara Pérez, Satish Penmethsa, Edith Valencia Martínez, Jaseem Pookandy, Igor Androsov and Joseph Thomas

 

And finally, to the lady herself, Natalya Murphy, who has given about 50 hours of her time this year to help others study towards this and the Integration Architecture exam this year. This is amazing content that will help people all over the world get certified in some of the most advanced areas of working with the hashtag#salesforce platform.

 

Thank you from the bottom of our hearts. We are really pleased to share the whole study group with you which can be found on YouTube. Don't forget to subscribe for more content :0)

Identity and Access Management Study Group

2 Kommentare
  1. 31. Dez. 2018, 23:26
    @Natalya Murphy is fantastic! I appreciate all her efforts and the efforts of my fellow study partners. Great work all!
0/9000