Skip to main content

#MFA토론 중인 항목 13개

I'm running into two issues and hoping someone can point me in the right direction.

 

Issue 1: MFA Temporary Verification Code A user has switched to a new laptop and doesn't currently have Windows Hello or another built-in authenticator configured. As a System Administrator, I attempted to generate a temporary verification code so they could log in, but received the error:

This occurs even though I'm already logged in as an admin and my device has a built-in authenticator available.

Troubleshooting already attempted:

  • Confirmed MFA is configured under Session Security Levels.
  • Temporarily adjusted MFA-related session security settings and retested.
  • Cleared browser cache/cookies.
  • Tested in both Chrome and Edge.
  • Verified active administrator session and attempted identity re-verification.
  • Same error persists.

Issue 2: Unable to Log a Salesforce Support Case I then attempted to log a Salesforce Support Case via Salesforce Help, but I don't have a "New Case"

option available anywhere in the support portal.  

 

Has anyone encountered either of these issues before?

  • Is there a prerequisite for generating temporary MFA verification codes that I might be missing?
  • Are there specific permissions or support entitlements required before the "New Case" option appears in Salesforce Help?

Any advice would be greatly appreciated. Thanks! 

 

#MFA

답변 5개
  1. 8월 20일 오전 4:25

    Hi @Katrina Luck

      

     I investigated this a bit further, and I believe the issue is most likely related to the fact that the Salesforce Setup interface runs on a different domain (my.salesforce-setup.com), while the org itself runs on my.salesforce.com. Combined with the recent passkey/MFA security changes, this appears to cause the problem.

    Fortunately, there is a simple workaround. Switch to Salesforce Classic and access the Connected App from there. In Classic, Setup is not redirected to the my.salesforce-setup.com domain, and the passkey verification works as expected, allowing you to reveal the Consumer Secret.

    We have also opened a Salesforce support case, as this appears to be an issue specific to the Lightning Setup experience.  

     

    https://trailhead.salesforce.com/trailblazer-community/feed/0D5KX00000jAN1h0AG

0/9000
Erik Laramee 님이 #Security에 질문했습니다

Hey Folks, 

 

We have a couple of contractors that are having issues creating passkeys for the upcoming phishing resistant mfa for privileged users update. Thus far, all the regular employees using company issues devices are having having any problems. For these two, one uses a mac and the other uses a virtual windows machine. Because of this, we believe this may be the problem. Does anyone have any experience creating passkeys with these cases? 

 

#Security  #MFA  #PhishingResistantMFA

답변 1개
0/9000
Sanjay Kumawat 님이 #Salesforce Admin에 글을 올렸습니다

Hello All, 

We are currently facing an issue with the Salesforce Connector for Google Sheets. We have been unable to export Salesforce reports to Google Sheets using the connector. 

We are receiving the following error message: 

"In order to get all of the report data, disconnect and re-authorize the Add-on from Salesforce using Help > Connection Information > Disconnect Add-on. Once disconnected, log in to Salesforce again using the Add-on." 

Based on our initial findings, we suspect that this issue may have been caused by the recent MFA enforcement in the Production environment.  

Each time a user tries to export a report, a new verification window opens and asks for an MFA verification code.

We are using the Salesforce Connector and have followed the instructions provided in the error message. After reconnecting, the export works only up to 2,000 records, and then the connection fails again.

Is there any workaround or recommended solution to prevent repeated MFA prompts and allow users to export reports successfully?

 

 

 

#Salesforce Admin  #Security  #MFA  #Salesforce_connector

댓글 5개
  1. 8월 14일 오후 12:03

    I met with Salesforce support. The option given to me was to suspend the MFA security changes from last month for 90 days. It was implied that google was aware of the issue and that it would likely be resolved before the 90 days was up.

0/9000

*** Important updates: MFA Enforcement Update: R1 Window Rescheduled to July 27-28 ****** Important updates: MFA Enforcement Update: R1 Window Rescheduled to July 27-28 ***We wanted to give you a heads-up that the R1 MFA enforcement window has been updated.We wanted to give you a heads-up that the R1 MFA enforcement window has been updated. Here's what you need to know:

 

What Changed

The R1 enforcement window has moved from July 21–22 to July 27–28.

 

Why the Change

We made this adjustment to address a few things:

  • Additional time was needed to fully process previously approved extensions
  • Some SSO users on orgs with approved extensions were being unexpectedly prompted for MFA

If You Have an Approved Extension

Keep in mind that approved extensions can take up to 48 hours to take effect, so you may still see MFA prompts during that window.

 

If your org has an approved extension but you're still being prompted for a passkey, please refer to this Knowledge Article for detailed guidance on specific use cases.

 

What's Not Changing

  • The MFA for All schedule remains the same
  • R2a, R2b, Japan & Korea, and all subsequent release groups are on their original schedules

Where to Find the Latest Info

The PRMFA Knowledge Article has been updated to reflect the new R1 window — that's your best source for the current schedule and details.

 

Have questions? Drop them in the comments below and we'll do our best to help! 

 

#MFA #Security

댓글 2개
0/9000
댓글 26개
  1. 7월 7일 오전 7:21

    good 

     

0/9000

While the intent behind Salesforce’s step-up authentication framework is both understandable and necessary given the increasing sophistication of data exfiltration risks, the current implementation introduces meaningful friction into core user workflows—particularly around reports and dashboards, which are among the most frequently accessed features for our business teams. 

 

From an adoption and usability standpoint, this experience is suboptimal. Requiring users to re-authenticate at the point of simply

viewing or running

a report—potentially multiple times per day—creates interruption in critical workflows, slows down data access, and adds cognitive and operational overhead. This is especially impactful in environments like ours where we are actively driving Salesforce adoption, encouraging teams to replace offline trackers, and reinforcing Salesforce as the single source of truth. 

There is a real risk that this added friction could inadvertently push users back toward less secure, manual alternatives (e.g., screenshots, exported files stored locally, or shadow tracking), which ultimately undermines both the adoption goals and the spirit of the security control itself. 

While the security objective is valid, the user experience could be significantly improved with more thoughtful enablement patterns and modern authentication approaches. Guidance that I would have assumed be offered by Salesforce themselves. 

For example:

  • Seamless, low-friction verification methods such as push-based approvals (e.g., Salesforce Authenticator prompts) should be the default and strongly encouraged over email/SMS OTP, which are slower and more disruptive.
  • Biometric-based authentication (Face ID, Touch ID) and passkey/passwordless experiences should be positioned as the primary path to reduce user effort during step-up challenges.
  • Clear guidance and best practices from Salesforce on how to configure session policies (e.g., optimal step-up intervals by role/use case) would help organizations strike the right balance between security and usability.
  • Proactive end-user enablement (tooltips, in-product guidance, and admin playbooks) would ensure users understand why the prompt is happening and how to complete it quickly.

Ultimately, achieving the right balance between security and usability

is critical. If step-up authentication becomes too intrusive, it risks becoming a barrier to productivity and platform adoption—particularly for high-frequency report users. 

A more user-centric approach—leveraging modern, fast, and intuitive authentication methods combined with stronger guidance for Salesforce—would help ensure this change enhances security

without compromising the momentum on we're making on adoption and workflow efficiency

 

Any suggestions?  

 

#MFA  #Security

0/9000
댓글 1개
  1. 5월 24일 오후 7:15

    Thank you @Michael Kolodner for the (as always) great article. The lack of clarity around whether 1password style cloud-passkeys will work or not is incredibly frustrating. With small nonprofits, they're in budgeting season so having to allocate precious funds to 1 or 2 new licenses in order to have broad coverage from a consulting partner is not going to go well, especially because it gets them right back to where they were (broad coverage support from partners) that they were before. And you're right, this is not winning any hearts and minds and partners supporting small np's are all pretty confused about what to tell our clients.

0/9000

I'm reviewing and trying to be prepared for the security roadmap enforcement dates.  We have a Marketing Cloud integration that was set up in 2021 by (with) an integration partner and a Salesforce Senior Manager (Solution Architect).  We have a dedicated license for the integration user, and it's set up as a System Admin at their direction.  From what I understand, API-only is not an option for MC Connector integration. There hasn't been a UI login for that user since 2021 when it was created.  It is not set up for MFA (not specifically exempted at this time, also not actively required either).  I'm trying to figure out whether the new requirements are going to break that integration when the mandatory enforcement begins.  I'd rather not touch it unless I have no choice - disruptions during our peak busy season are extremely unpopular.  Could use some clear, specific guidance.  Thank you! 

 

#MFA  #Marketing Cloud

답변 1개
  1. 5월 16일 오전 1:40

    Based on Salesforce official documentation, I would separate this into two topics:

    1. MFA is required for human or interactive logins. Marketing Cloud Engagement documentation states that MFA is required for users accessing the platform directly.
    2. Salesforce also documents that MFA isn’t required for system integration login types via API. However, if an admin or anyone else logs in interactively as that integration user, MFA is required for that login.

    For Marketing Cloud Connect specifically, the Salesforce Integration User License / API Only System Integrations profile is not compatible with Marketing Cloud Connect, according to Salesforce documentation. So the “API-only user” approach is not the right path for this connector.

    My interpretation is: if the user is only being used by the Marketing Cloud Connect integration/API flow and no one logs in interactively with it, MFA should not break the API integration based on the current documentation. But because the user is a System Administrator, and Salesforce is enforcing stronger MFA requirements for privileged users, I would confirm this with Salesforce Support before the enforcement date and make sure MFA is registered in case the user ever needs an interactive login for maintenance, reconnecting, or refreshing credentials.

     

     

    https://help.salesforce.com/s/articleView?id=mktg.mc_overview_mfa.htm&type=5

0/9000
댓글 2개
0/9000

Hi,

I am trying to implement MFA for community users with apex so that when they log in some users will need to use the Salesforce Authenticator app to complete the login

I am 1st trying to make the user register with the authenticator app

UserManagement.registerVerificationMethod(Auth.VerificationMethod.SALESFORCE_AUTHENTICATOR, '/');

but I get:

11:43:03.4 (187484011)|EXCEPTION_THROWN|[17]|System.NoAccessException: Insufficient Privileges: You do not have the level of access necessary to perform the operation you requested. Please contact the owner of the record or your administrator if access is necessary.  

 

It seems it returns a page reference with sys admin context but not in community user context

Also when I query TwoFactorMethodsInfo I get

sObject type 'TwoFactorMethodsInfo' is not supported

 

What am I missing, the MFA is not enabled at all ?

I also tried registering SMS and EMAIL as a verification method, those return a page reference (it seems to verify the email/phone number) but when I redirect to the page I get 302 and get redirected to the same page I came from

댓글 10개
  1. 2025년 2월 10일 오후 5:41

    Hey @Jani Ruohomaa

     

    Were you able to implement this? I am trying to implement this currently similar to this. I am using flow from this example :

    https://help.salesforce.com/s/articleView?id=xcloud.security_login_flow_examples.htm&type=5

     

     

    However, I am unable to access the TwofactorInfo object from the flow even I have given myself the "Manage Multi-Factor Authentication in API" permission. Is there anything other than this that I am missing? 

     

    Thanks, 

    Venky

0/9000