Skip to main content

#Security193 discutindo

Hello All, 

We are currently facing an issue with the Salesforce Connector for Google Sheets. We have been unable to export Salesforce reports to Google Sheets using the connector. 

We are receiving the following error message: 

"In order to get all of the report data, disconnect and re-authorize the Add-on from Salesforce using Help > Connection Information > Disconnect Add-on. Once disconnected, log in to Salesforce again using the Add-on." 

Based on our initial findings, we suspect that this issue may have been caused by the recent MFA enforcement in the Production environment.  

Each time a user tries to export a report, a new verification window opens and asks for an MFA verification code.

We are using the Salesforce Connector and have followed the instructions provided in the error message. After reconnecting, the export works only up to 2,000 records, and then the connection fails again.

Is there any workaround or recommended solution to prevent repeated MFA prompts and allow users to export reports successfully?

 

 

 

#Salesforce Admin  #Security  #MFA  #Salesforce_connector

4 comentários
0/9000

I am trying to create an External Client App in my oldest personal dev org (ca. 2013). When I attempt to obtain the client id and secret, I get an insufficient permissions error. My user has the standard System Administrator profile which is tied to the Salesforce license. When I search for the new External Client App permissions on the profile they are not there, so I created a custom perm set and gave it the permissions. Now when I try to assign the perm set I get:    The user license doesn't allow the permission: View External Client App Consumer Secrets in Metadata    Any ideas on how to resolve or workaround this?    

5 respostas
  1. Hoje, 12:45

    Is there any update on this issue?

0/9000

Hello Trailblazers, 

 

I've recently run into a frustrating issue with Salesforce's mandatory Lightning Login Enrollment feature. I had signed up for this verification method and was able to log in successfully, but for the past couple of days, I haven't been able to log in. I keep getting the message:  

"To log in, you need both a higher access level and identity verification method. 

Contact your administrator to gain login access."

I'm not sure what's causing this. Please note that I've already tried clearing my browser cache and attempting to log in from a different browser, but with no luck. I was able to log in before using Salesforce Authenticator as my verification method. Now, every time I try to re-register on Salesforce Authenticator, I get the same message.

Has anyone faced a similar issue?  

2 respostas
  1. Hoje, 12:27

    I've just "sorted" this issue with one of our users. The problem is that the new passkeys are not compatible with the lightning login. You need to disable this for the user: 

    I've just

     

    If you lookup the Passkey/Security Key in the database it should show it's active in the slot above Lightning Login, but it's not, it's in a new space. You need to scroll all the way down to a "Built-in Authenticator" section.  

     

    image.png

     

     

    If for whatever reason a user needs to login on a new device they will need to delete the passkey from their current device and you will need to remove this from their profile and then when they login they will need to use their authenticator app to setup a new passkey on the new machine. It's a nightmare.

0/9000

Hi everyone,   

I have a question regarding the upcoming MFA enforcement for all employee users.   

Let's consider this scenario:

If organization has five administrators who all use the same System Administrator username and password (shared login). The email address associated with that Salesforce user belongs to me.

When Salesforce prompts us to register a Passkey, I complete the registration using my device because the email is mine. After that, when another administrator tries to log in using the same shared credentials, Salesforce requires the registered passkey, which only I have. As a result, the other admins are unable to log in.    How should organizations handle this situation?

  • Is sharing one System Administrator account no longer supported with passkeys?
  • Does Salesforce expect every administrator to have their own individual user account?
  • If a shared admin account must be used (for legacy reasons), what is the recommended approach to satisfy the new MFA/passkey requirement?

I'd appreciate any guidance or best practices from the community. Thanks!    

2 respostas
  1. Ontem 19:18

    I am a single admin and cannot get a passkey setup. I go to add a passkey, then the Create a Passkey window opens, and the key is created. I try logging on with another browser and scan the QR code. This starts my loop of requesting a passkey because it does not recognize my phone.  I follow the direction in the Release and from a few other sites, but nothing works.  Never have found directions from Salesforce very easy to follow.  I have reset my password twice already and worried that I will not be able to log back in tomorrow.  How do I get my cellphone to be recognized by the QR code? I look at my personal profile, and I have a passkey but cannot access Salesforce from any other browser.  

0/9000

Hi everyone, 

I'm experiencing an issue in a Salesforce Sandbox when trying to access: 

Setup → App Manager → View App → Manage Consumer Details 

 

When I click Manage Consumer Details, Salesforce opens the Verify Your Identity dialog, but the authentication immediately fails with the following error: 

There are no built-in authenticators available to this browser. 

Verify Your Identity fails with 'There are no built-in authenticators available to this browser' when opening Manage Consumer Details

 

Environment:

  • Salesforce Sandbox
  • Google Chrome

 

What I've already verified:

  • Touch ID is correctly registered as my authentication method.
  • Touch ID works correctly for other authentication requests.

 

From what I've investigated, it appears that the Verify Your Identity dialog may be rendered inside an internal iframe, and the browser is therefore unable to access the registered authenticator. 

 

Has anyone encountered this issue before? Is this a known Salesforce or Chrome limitation, or is there a configuration or workaround that resolves it? 

 

Any help or suggestions would be greatly appreciated. 

 

Thank you! 

 

 

 

#Security

9 respostas
  1. Ontem 18:22

    Completely unacceptable. Yet another bug open for months, but this time while there's a workaround it should be fixed with how expensive licenses are. This is authentication and security... no workarounds are valid.

0/9000

Hello,       I am assuming a lot of people are having issues with the MFA regulations that have come up.       Has anyone found a workaround for multiple computers for one Salesforce account or Multiple users for one Salesforce account and the passkeys?       I am a System Admin with another person and we share a login, due to the client not wanting to purchase more licenses. She setup the passkey on her computer, but when prompted on my computer, I can not use the passkey option.       Has anyone found any solution or workaround?       Thank you. 

3 respostas
  1. 4 de ago., 13:51

    You can register the passkey for one of the users from login screen and then get a temporary code generated from the user record page and try to login from the 2nd user's laptop using temporary code and add the passkey from the 2nd user system, this way you should be able to use single account for both.

    PS - I have not tried this myself I'm just suggesting this based on options I'm aware of in Salesforce.

0/9000

 Can anyone suggest why certain list views of Lead object are disappearing abruptly in my Salesforce production org multiple times? Each Time we are creating the disappeared list view and again they are disappearing.Any kind of suggestions are hearty welcome.

10 respostas
  1. 11 de ago., 16:45

    Filters are fine, and there are multiple records under the view. I use/ show this filter link in the flow: Email alert. The user receives an email alert and can see the list view for one week or so, and then it magically disappears. Looks like a Salesforce bug to me.

0/9000

I want to understand what's the actual use case of Service Cloud License, so that I can evaluate how many license our org will require .  I checked without license,users from different  Profiles can see Service Console App, also cases can be assigned to them.

4 respostas
  1. 11 de ago., 01:10

    thanks for your answer  @Steven Trumble

    , We don't have requirement of omnichannel and Einstein features etc. So If I have team of 20 people who will work on Case Management, Service Cloud User feature license need to be given to all? 

    Or if I give to few still, milestones, entitlelments etc. will work for all cases

0/9000

⛰️ 🔐 New Hands-on Workshop for Premier & Signature Admins: Secure the Org: Find and Fix Vulnerabilities (ADX012)

 

 Misconfigured security settings are one of the leading causes of data breaches. In this 90-minute instructor-led workshop, you'll step into the role of an internal security auditor to identify and fix real Salesforce vulnerabilities across the most common misconfiguration areas. 

 

This workshop was adapted from a fan-favorite capture-the-flag game that has been a hit at live Salesforce events — now available virtually so more admins can play! This practical workshop is for:

  • Newer admins — you'll find the challenges approachable and manageable. The hands-on format makes security feel less daunting and more actionable
  • Seasoned practitioners — you'll likely discover security settings you haven't previously been aware of
  • All learners — challenges are independent of each other, so you can move at your own pace, skip ahead, and circle back with no pressure

Sessions are live and available!

  • Fri Jul 31 — 9:00am ET [AMER]
  • Mon Aug 3 — 3:30pm ET [AMER]
  • Tue Aug 11 — 10:00am CET [EMEA]
  • Check the session listings for more workshops across regions 

➡️ Premier and Signature customersRegister today on Trailhead Academy — Course code: ADX012

 

#Security

12 comentários
0/9000

*** Important updates: MFA Enforcement Update: R1 Window Rescheduled to July 27-28 ****** Important updates: MFA Enforcement Update: R1 Window Rescheduled to July 27-28 ***We wanted to give you a heads-up that the R1 MFA enforcement window has been updated.We wanted to give you a heads-up that the R1 MFA enforcement window has been updated. Here's what you need to know:

 

What Changed

The R1 enforcement window has moved from July 21–22 to July 27–28.

 

Why the Change

We made this adjustment to address a few things:

  • Additional time was needed to fully process previously approved extensions
  • Some SSO users on orgs with approved extensions were being unexpectedly prompted for MFA

If You Have an Approved Extension

Keep in mind that approved extensions can take up to 48 hours to take effect, so you may still see MFA prompts during that window.

 

If your org has an approved extension but you're still being prompted for a passkey, please refer to this Knowledge Article for detailed guidance on specific use cases.

 

What's Not Changing

  • The MFA for All schedule remains the same
  • R2a, R2b, Japan & Korea, and all subsequent release groups are on their original schedules

Where to Find the Latest Info

The PRMFA Knowledge Article has been updated to reflect the new R1 window — that's your best source for the current schedule and details.

 

Have questions? Drop them in the comments below and we'll do our best to help! 

 

#MFA #Security

2 comentários
0/9000