I'm working with a US government agency. Currently, all users log in to the system using SSO, which authenticates them by matching their Active Directory User Principal Name (UPN.) Users log into Active Directory by putting their PIV card into their laptop and entering their PIN number. Once they are logged in and on the VPN, Salesforce logs them in via SSO once they go to the Salesforce MyDomain page. We are using trusted IP ranges set to the VPN public IP addresses.
We allow admins to log in via the login page. My questions are:
- Does the SSO (PIV card/PIN/Trusted IP ranges) meet Salesforce's requirements for MFA as of 2/1?
- Are we OK to only set admins (who can log in with a username/password) up to require another form of MFA (e.g. Salesforce Authenticator)? Thanks!
Thank you -- my concern is that the flowchart I saw indicated a requirement of logging in with a username and password and then having another form of authentication in place. Logins from the US federal government are different in that your card acts as your username, so the process isn't an exact match for the requirements as written, but it is very secure and requires something you have (a PIV card/smart card with its certificate registered into AD) and something you know (your PIN.) There are a huge number of people who work for the US government who log into AD this way and if Salesforce accepts the PIV card + PIN method as MFA, that covers all of our non-admin users.
I'd love for Salesforce to add this as an acceptable method in the MFA documentation. My thought is that most government cloud users log in via SSO and will need a definitive answer from Salesforce on this in the next few months.