Skip to main content

A few small orgs I'm involved with give all users the Modify All Data privilege. 

 

The reason is to make NPSP function properly.  Ex: Manage Household --> move a Contact from one single-Contact HH Account to another (due to marriage or data cleanup).  NPSP tries to delete the now-empty source HH Account. 

 

While Modify All Data is not

required

for this (only Delete on Account is required I think), in small orgs with messy record ownership, it seems to be the easy way to make sure an error never happens. 

 

My question then: In practice for small NPSP-using orgs, will all users end up being "privileged" and therefore require Phishing Resistant MFA?  Or is there a better way?  What does the community recommend as best practice here to keep NPSP running smoothly for all users without too much authentication aggravation? 

 

Emphasis on

practical for small orgs 

who don't have immediate access to a sysadmin who knows what to do when NPSP throws an error. 

 

(I'm freaking out along with the rest of the community about the upcoming security changes...) 

 

@Salesforce.org System Administrators

 

 

#Salesforce Admin

4 réponses
  1. 3 juin, 19:00

    Hi @John Fine

    - great to see your name! 

     

    I don't think it matters really how large, small, or resourced an organization is. If the user has the *System Permission* for Modify All Data, then they must have phish-resistant MFA. And I'd argue, given everything happening in the world right now, they should.  

     

    There isn't a good reason for a user to have Modify All Data, again at the *system* level, to work around these issues in NPSP. They can have it at the Object level on Account instead. 

0/9000