Skip to main content

#Multi-Factor-Authentication11 人がディスカッション中

While doing  Superbadge: Multi-Factor Authentication and Single Sign-On Settings - I am changing mail and getting verification code on noreply@example.com

 and also if i get link on my mail then too i need the password for the user  

 

#Trailhead Challenges  #Trailhead Superbadges  #Salesforce Developer  #Multi-Factor-Authentication #SingleSignOn

2 件の回答
  1. 9月29日 17:08

    Hi @Nikhil Kawale

    , I discussed it with the salesforce support team , they guided me  

    So, I followed these steps - open 

    Login Access Policies ->Administrators Can Log in as Any User  , then you can login as user -> change password -> verify the mail -> wait for 24 hours ->  and then continue doing the challenge.

0/9000

I have one Production/Enterprise org connected to two Sandboxes:

  • DEV Sandbox
  • UAT Sandbox

Both Sandboxes were recently created, and I haven't logged into either Sandbox from any device yet.

When I try to log in to either Sandbox using my Sandbox username and password, Salesforce asks me to authenticate using a passkey.

Initially, I had a passkey saved in Microsoft Edge, but I removed it while troubleshooting. Now, when I try to log in, Salesforce gives me the option:

“iPhone, iPad, or Android device”

which displays a QR code.

When I scan the QR code using my iPhone, my phone opens Google Password Manager and shows:

I am still able to log in successfully to my Production org, and I am a System Administrator there.

My question is:

Since I still have access to the Production org but cannot log in to either Sandbox, is there any way to recover/reset the Sandbox passkey or generate a temporary verification code so that I can regain access to the Sandboxes?

I don't want to delete or recreate the Sandboxes. I just want to recover access to the existing DEV and UAT Sandboxes.

Any guidance on the correct Salesforce-supported recovery process would be greatly appreciated. 

 

#Multi-Factor-Authentication

1 件の回答
  1. 9月23日 4:04

    Hi , 

     

     

    If no administrator can log in to the Sandbox, the most likely option is to open a case with Salesforce Support and request assistance in restoring access

0/9000

Hey all, 

We are running into issues accessing the mobile app since MFA has been enforced for privileged users. 

  1. If a user sets up the Built-in Authentication on desktop, they are not able to login to mobile. Our company only allows Windows Hello authentication on desktop, and users are unable to "Verify Identity" in iOS when this is added on desktop. The screen is frozen on this even when using "Login for Admin."
  2. We have gone into Salesforce Classic on the mobile browser and added a passkey, but it doesn't work in the app. 
  3. If we delete the Built-in Authenticator on desktop and add a passkey for mobile, it then requires users to have their phones to login on desktop. 

None of these scenarios are ideal, and I'm wondering if anyone has been able to use Window Hello to authenticate desktop and then directly login on mobile with the their Face ID, Touch ID, or passcode? We have found hacky ways to get people logged in with generating a temporary code then having them setup a passkey etc, but it seems like the app should automatically guide users to setup a mobile passkey even when there's an authenticator for desktop? Is this a bug with MFA and mobile because it doesn't seem like this should be expected behavior? 

 

#Multi-Factor-Authentication  #Salesforce1 Mobile App  #Salesforce_Mobile_App

3 件の回答
  1. 9月9日 19:55

    The Salesforce Help article at https://help.salesforce.com/s/articleView?id=005391003&type=1 does provide instructions to set up a separate passkey on a mobile device in addition to the one for desktop. It's pretty pooly written and I suspect that there are many edge cases in which it doesn't work, but I got it to work on iOS, committing the passkey to the native Passwords app.

0/9000

Hi everyone,  

 

I was wondering if anyone has experience adding multiple passkeys to the same user account.  

I have set up on key already with the password manager, but am trying to set up a second one on the phone only. The issue is the second attempt will say no matching passkeys found as it is already searching for existing.  

 

Alternatively, is it possbile to keep the passkey setup with the password manager, and add  a second physical security key in addition, and have the option to use either one of them? 

 

Thanks for the help!  

 

Marie Olsen 

 

#Login Attempt  #Multi-Factor-Authentication  #Security

2 件の回答
  1. 8月15日 19:47

    Hi Marie - yes, Salesforce supports registering more than one passkey/security key on the same account, and you can use any of them to log in. The behavior you're hitting is the classic passkey gotcha: adding a second one has to be done from the registration flow in your settings, not from the login screen. 

     

    Here's what's happening: at the login prompt, the browser/OS is trying to authenticate, so it searches for an existing passkey - that's the 'no matching passkeys found / searching for existing' message. That flow only looks for credentials already registered; it will never create a new one. So the second passkey has to be enrolled from inside your account. 

     

    To add another one: log in with your existing (password-manager) passkey, then go to your personal Settings and find the security-key / built-in-authenticator registration area (in Lightning it's under your personal Settings - look for Advanced User Details, which has the register links for a security key or built-in authenticator). Start the registration there, and when the passkey dialog appears, choose the new target - your phone, or 'use a different device' - rather than the saved password-manager one. That enrolls a second, independent credential. 

     

    On your alternative question: yes, you can absolutely keep the password-manager passkey and add a physical security key as well. Register the physical key the same way (from settings, not login), and at sign-in you can use whichever one you have on hand. Mixing a platform passkey with a roaming security key is exactly the kind of redundancy passkeys are meant to allow - having a backup method registered is a good idea. 

     

    One thing to watch: start each new registration from your account settings while you're already logged in, and pick the specific device when the OS dialog pops up - browsers love to default back to the passkey you already have. 

     

    Hope that gets your second one enrolled!

0/9000

Been on hold for hours for support - Still holding, day 5+, tried to use the agent but it cut me off, cases can't be created.  In the meantime, anyone know how to resolve this as I wait......to create a case, or talk to someone.  

 

 I am the sole System Administrator for our Salesforce organization and have become locked out of my account after accidentally deleting the only registered Windows Hello passkey during testing. While my username and password are still valid, Salesforce requires MFA and no longer recognizes any authentication method, leaving me unable to access the organization or reset my own MFA settings. I have already attempted all available recovery options, including "Having Trouble?", checking Chrome and Windows for saved passkeys, and trying multiple devices and browsers, without success. As there are no other administrators in the organization, I am requesting assistance resetting my MFA registration, removing the deleted passkey, issuing a temporary verification code, or otherwise allowing me to register a new authentication method after verifying my identity and ownership of the organization.  

 

#Multi-Factor-Authentication

1 件の回答
  1. 8月4日 15:35

    After holding for 30 minutes again today, just got cut off.  Please call back.  Seriously what is wrong with Salesforce support nowadays. 

0/9000