Hi,
After running the report for 'Security and Access', the 'Active Internal Users' tab has a user flagged with a score of '1' for this reason:
{
The component Service_Account_ABC (005OQ0000064PCT) has a score of 1 because of the following reasons:User is logging directly without MFA: This user is logging in directly to Salesforce without using MFA (Multi-Factor Authentication). And this user has not the MFA bypass enabled. Please work with your user to make them use MFA for better security.
}
This is a service account, and there was a change of Username and Email fields to new owner on 29 April 2026. The new owner login for the first time using the 'Username' and 'Password'. As this is a service account, there is no SSO or MFA and the reason highlighted is understandable.
May I know for how long will this user to highlighted? I'm asking because today is 18 May 2026 already and it is still highlighted whenever I run 'Refresh'. Any comments or explanation is appreciated! =)
Thanks in advance!
Regards,
Teck Lung
Hi Teck Lung!
The important point here is that Org Check is evaluating the user's current authentication/security configuration, not simply the date when the username or email was changed.
If the service account is still logging directly into Salesforce without MFA and there is no MFA bypass configuration, the finding can continue to appear each time you refresh the report. The 29 April login would not normally cause the finding to disappear after a fixed period.
Since this is intentionally a service account, I’d verify whether the account can use an appropriate non-interactive authentication method instead of relying on username/password, or review the applicable MFA/bypass configuration based on your organization’s security requirements.
If you expect Org Check to exclude this specific service account, I’d also check the current Org Check rules/configuration for the Active Internal Users check, as the scoring is driven by that rule.