Skip to main content

#MFA Requirement0 personne en discute

yuyu ma (Engineer chez TES) a posé une question dans #MFA

Morning everyone,

Is there any ways for Andriod phone to install Salesforce Authenticator? I couldn't find the link in Saleforce setup. Thank you guys in advance~

 

#MFA  #MFA Requirement

4 réponses
0/9000

📣 ⭐ Calling all MFA Rockstars! We Want You to Present at Dreamforce ⭐ 📣  

 

Dreamforce is in September, but the call for speakers is open now. Have you enabled MFA? If so, what's your MFA story? What were the challenges and successes? How has MFA for Salesforce helped secure your environment?

 

If you're interested in completing a speaker submission, let us know in the comments. We would love to hear your MFA story!

 

Not sure what an MFA story would look like? Check out Shiseido's story: https://sfdc.co/mfa-shiseido

 

#MFA - Getting Started #MFA #Salesforce MFA #MFA Requirement

2 commentaires
0/9000

📣 🚨 Questions about the MFA requirement? Check out our MFA Ask the Expert Sessions!🚨 📣

 

Our MFA Getting Started Webinars and MFA Ask the Expert sessions are now open to all customers! Watch the recordings or join us for our upcoming MFA Ask the Expert sessions on Tuesday, Feb. 8, at 10 a.m. PST and Tuesday, Feb. 22, at 10 a.m. PST. 

 

➡️  Check out the Customer Success Calendar, find a session and time that works best for you, and get your MFA questions answered by Salesforce MFA experts.

📣 🚨 Questions about the MFA requirement?

#MFA - Getting Started #MFA #Salesforce MFA #MFA Requirement #MFA Webinar #CommUpdates

4 commentaires
0/9000

how can i see mfa or SSO status ( enabled or disabled ) as a view on my user list in salesforce

can i be helped as i want to see all the active users in my users list with the visibility of their status in MFA and SSO whether they are enabled or no , as per the attached pic, SF community can be helped on this, as i have Sales cloud and also service cloud and health cloud

2 réponses
  1. 6 déc. 2021, 20:19

    i tried  that way, still i cant see it , please guide me if it is ok, to request you for the same,

0/9000

We have an website integration account running which is required for our setup. How is this going to work with the MFA? Because if that stops working, basically everything does.

 

What kind of solution do you have for that?

1 réponse
  1. 18 oct. 2021, 13:09

     Hi @Duncan Verhagen,   As per my understanding, multi-factor authentication adds an extra layer of protection against common threats like phishing attacks, credential stuffing, and account takeovers.

     Implementing MFA for products built on the Salesforce Platform is one of the most effective ways your company can increase the security of your Salesforce data.

     You can prevent unauthorized account access with Multi-Factor Authentication (MFA).

     Refer the link for more information: https://www.salesforce.com/products/platform/multi-factor-authentication/  Thanks, 

    Akansha

0/9000

We are implementing MFA in our salesforce instance. Most users will be signing into to salesforce using SSO. We decided to use our SSO's MFA, but when I look at the metrics it doesn't display that any SSO users have signed in with MFA. Is this only because the MFA is outside of salesforce?

 

#MFA - Getting Started

 

@* MFA - Getting Started *

3 réponses
  1. 8 oct. 2021, 15:17

    Correct, Salesforce does not capture the MFA information from your SSO login flow.

0/9000

I'm working with a US government agency.  Currently, all users log in to the system using SSO, which authenticates them by matching their Active Directory User Principal Name (UPN.)    Users log into Active Directory by putting their PIV card into their laptop and entering their PIN number.  Once they are logged in and on the VPN, Salesforce logs them in via SSO once they go to the Salesforce MyDomain page.  We are using trusted IP ranges set to the VPN public IP addresses. 

 

We allow admins to log in via the login page.    My questions are:

 

  • Does the SSO (PIV card/PIN/Trusted IP ranges) meet Salesforce's requirements for MFA as of 2/1?
  • Are we OK to only set admins (who can log in with a username/password) up to require another form of MFA (e.g. Salesforce Authenticator)?   Thanks!

#MFA  #SSO  #SAML SSO  #MFA Requirement

2 réponses
  1. 24 août 2021, 15:01

    Thank you -- my concern is that the flowchart I saw indicated a requirement of logging in with a username and password and then having another form of authentication in place.  Logins from the US federal government are different in that your card acts as your username, so the process isn't an exact match for the requirements as written, but it is very secure and requires something you have (a PIV card/smart card with its certificate registered into AD) and something you know (your PIN.)  There are a huge number of people who work for the US government who log into AD this way and if Salesforce accepts the PIV card + PIN method as MFA, that covers all of our non-admin users. 

     

    I'd love for Salesforce to add this as an acceptable method in the MFA documentation.  My thought is that most government cloud users log in via SSO and will need a definitive answer from Salesforce on this in the next few months.

0/9000

This comment is specifically addressing enabling MFA via SSO.

 

I’ve been following the MFA 2022 requirement since it was first announced. As it stands today, there is no way for Salesforce to verify whether MFA was used if a user logged in via SSO. All the verbiage I’ve seen on this requirement, whether the updated FAQ or Jim Alkove email, use words like “should” or “necessary”, but fact of the matter is it's not a requirement if it cannot be technically enforced.

 

If the MFA requirement goes into effect today, for SSO users it means the following:

  1. Do not enable the "Multi-Factor Authentication for User Interface Logins" user permission
  2. Users can continue to login to Salesforce via SSO with or without MFA

Complete both steps above and the MFA requirement is satisfied. Whether MFA is enabled on SSO is not important because Salesforce cannot verify. I know Salesforce keeps saying MFA should be enabled for SSO, but again, does this requirement matter if it cannot be technically enforced?

 

I post this summary for a couple of reasons.

1. Someone in Salesforce please reply and tell me I’m wrong. If my assessment is indeed correct, it is a huge loophole in the overall MFA requirement roll-out. How does Salesforce plan to address this?

2. Someone in a recent comment mentioned Salesforce may be working on the technicality of enforcing MFA on SSO. If this is the case, this requirement was prematurely announced. 10+ months seem like a long time, but with this uncertainty hanging overhead there is very little time to implement and test should SSO configurations need to be updated somehow.

 

The least of which Salesforce can do right now is make the SSO uncertainty clear in the FAQ. On the other hand, I also understand it’s a Catch-22 where any further clarification would be publicly acknowledging this SSO loophole and having no good response for it.

3 commentaires
0/9000

Hi Community!

 

We have an issue with the MFA requirement. For security reasons, our users are not allowed to have their mobile phones in the office, therefore they cannot authenticate. Purchasing physical security keys is a no-go in terms of logistics and plannification. 

 

We already use Okta as our SSO Provider, is there any way for us to fulfill the requirement given our circumstances? While we do realise that this is an edge-case, we also believe we're not the only ones in this predicament.

1 commentaire
0/9000

We are looking re-enabling our SSO, which is setup using an LDAP connection.  The SSO uses MFA.  Does this manner of SSO with MFA count for the MFA requirement, or is it similar to SAML and not yet supported in SSO with MFA?

 

Thanks!

1 commentaire
  1. 13 avr. 2021, 00:01
    We have a similar use case. Looking forward to get some response from Salesforce.
0/9000