Skip to main content

I recently implemented Two-factor Authentication via a Permission Set for users with the System Administrator profile.  My hope was to start with the PS and then apply it at the Profile level to avoid the maintenance.  Our organization refreshed our Full Sandbox and we realized that the System Administrators with the Two-factor PS were not able to login to the refreshed sandbox.  Luckily, I had an account without the PS that I used to login and remove the PS from the System Admins.   I’d still like to apply Two-factor via Profile, but am not sure how to address refreshes going forward.  My goal is for all System Admin UI logins to require Two-factor, so creating a sperate profile without it is not a good fit.

 

Any thoughts?

 

Thanks,

 

Stephen

6 comentários
  1. 2 de dez. de 2019, 20:53
    @Stephen Jones two-factor via email is not a standard configuration in Salesforce, but rather is used for Identity Confirmation (login from new browser), but that shouldn't happen on the first login. So, you may have a custom Login Flow enabled. Let me know what you find out. Thx.
0/9000