This comment is specifically addressing enabling MFA via SSO.
I’ve been following the MFA 2022 requirement since it was first announced. As it stands today, there is no way for Salesforce to verify whether MFA was used if a user logged in via SSO. All the verbiage I’ve seen on this requirement, whether the updated FAQ or Jim Alkove email, use words like “should” or “necessary”, but fact of the matter is it's not a requirement if it cannot be technically enforced.
If the MFA requirement goes into effect today, for SSO users it means the following:
- Do not enable the "Multi-Factor Authentication for User Interface Logins" user permission
- Users can continue to login to Salesforce via SSO with or without MFA
Complete both steps above and the MFA requirement is satisfied. Whether MFA is enabled on SSO is not important because Salesforce cannot verify. I know Salesforce keeps saying MFA should be enabled for SSO, but again, does this requirement matter if it cannot be technically enforced?
I post this summary for a couple of reasons.
1. Someone in Salesforce please reply and tell me I’m wrong. If my assessment is indeed correct, it is a huge loophole in the overall MFA requirement roll-out. How does Salesforce plan to address this?
2. Someone in a recent comment mentioned Salesforce may be working on the technicality of enforcing MFA on SSO. If this is the case, this requirement was prematurely announced. 10+ months seem like a long time, but with this uncertainty hanging overhead there is very little time to implement and test should SSO configurations need to be updated somehow.
The least of which Salesforce can do right now is make the SSO uncertainty clear in the FAQ. On the other hand, I also understand it’s a Catch-22 where any further clarification would be publicly acknowledging this SSO loophole and having no good response for it.