Hey everyone,
A few months ago our I.T. team enabled MFA for Okta, which is our identity provider for most apps in our organization including Salesforce. From what I understand, now that we have this solution in place it meets the upcoming requirement.
However, I'm stuck in a few places so would love to check my thinking with other people who use Okta at their orgs.
- From what I understand, I'd only need to update Session Settings to move Okta SSO to High Assurance. Is this correct?
- We'd also want to disable login access from login.salesforce.com to ensure folks use Okta as expected. I'm familiar with the steps as outlined here, but what isn't clear is how this would affect our Admin users who do need to retain this access. Any suggestions for this piece, or different ways to approach this?
- Lastly, we have a particular use case where a few users would need to launch Salesforce on an external device like an iPad or laptop to display a screen we use as a "sign in" sheet. They'd also still need to access Salesforce on a different device at the same time. While this isn't an example of shared usage because the same person would be signing in using their credentials, I'm curious if this may cause any access issues.
9 risposte
Hi @Lindsey Adams, did you ever get confirmation to this question
- From what I understand, I'd only need to update Session Settings to move Okta SSO to High Assurance. Is this correct?
After reading this thread there seems to be some that say Yes updating session settings to High Assurance makes you MFA compliant. Others say no, you still need a second form of authentication such as an Authenticator App.
Thanks in advance for your help!