Skip to main content

Hello! Here's the full recap from yesterday's AMER AMA June 10, 2026. Thank you to everyone who attended and special shout to this month's panelists @Rachel Park Brayboy and @Kathy Waterworth and of course our host @Rob OBrien

.  On to the recap!  

 

Q: Looking for ideas on a 2nd login method for phishing-resistant MFA. I currently use a YubiKey.

A: With Salesforce's upcoming security enhancements, many organizations are evaluating backup authentication methods and phishing-resistant MFA options. 

 

One recommendation shared was to maintain at least two authentication methods to help prevent account lockouts. Options discussed included:

  • An additional hardware security key, such as another YubiKey or a Google Titan Key
  • Platform-based biometrics and passkeys
  • Passkeys stored in supported password managers

Community Insights

  • One attendee shared that Salesforce is expected to expand support for additional security key options in the future, including the ability to register a second YubiKey.
  • Another attendee asked whether passkeys stored in password managers such as 1Password or Bitwarden would be considered phishing-resistant. The group discussed that passkeys stored in supported password managers are generally considered phishing-resistant authentication methods.
  • It was noted that there is an active discussion on this topic in the Trailblazer Community for anyone looking to continue the conversation.

Resources:

Q: I'm curious how folks are planning to communicate with their users regarding the upcoming security changes, especially for step-up authentication for reporting!

A: The group discussed the importance of proactive communication and user education ahead of Salesforce's upcoming User Verification requirements. Some recommendations included:

  • Creating visual guides and walkthroughs so users know exactly what to expect
  • Sharing Salesforce documentation ahead of time
  • Helping users recognize legitimate verification prompts such as passkey, email, or SMS authentication requests

Depending on your organization's configuration, users may be prompted to re-authenticate after a specified cooldown period when accessing reports and dashboards. Organizations should begin preparing users now so the experience is expected rather than disruptive. 

 

Community Insights

  • One attendee shared that users with a valid email address on their User record can receive an emailed verification code for re-authentication and that this may be their primary approach.
  • Another attendee shared that their communications are focused on protecting organizational and constituent data, helping users understand the security benefits behind the change.
  • The group discussed that while the additional authentication may sound burdensome, many users may only encounter prompts periodically depending on how often they access reports and dashboards.
  • Several attendees emphasized that organizations using SSO should still review Salesforce's User Verification requirements carefully, as additional verification methods may still need to be configured.

Resource:

 

https://help.salesforce.com/s/articleView?id=005321566&type=1

 

Q: Hello all. I need tips and tricks on how to handle contact affiliations and keep them updated.

A: Maintaining accurate affiliation records is essential for preserving relationship history and improving reporting quality. Some best practices discussed included:

Track the Full Affiliation Lifecycle

  • Record both Start and End Dates whenever possible.
  • When a contact changes organizations, retain the historical affiliation and update its status to reflect that it is no longer current.
  • Create a new affiliation record for the contact's current organization rather than overwriting historical information.

Leverage Primary Affiliation Fields

  • Use the Primary checkbox or Primary Business Organization field to identify the contact's current primary organization.
  • This helps ensure communications, segmentation, and reporting remain accurate.

Use Automation Where Possible

  • Enable Automatic Affiliation Management within NPSP or EDA where appropriate.
  • Build flows that automatically update affiliation statuses when end dates have passed.
  • Consider requiring users to provide an inactive reason when marking affiliations as former or inactive.

Ongoing Maintenance

  • Use reports, list views, and inline editing to review and update affiliation records in bulk.
  • Avoid deleting historical affiliation data whenever possible, as it provides valuable context for future reporting and relationship management.

Q: Hi! Our organization (using NPSP) is starting to explore Screen Flows in Experience Cloud Sites. We have run into an issue when we are testing the form (that creates/matches contact and creates a custom object) what gets put into Salesforce is not what was in the form. What gets put into Salesforce is a record on an existing contact. Have you run into this before? Any tips for troubleshooting?

A: The discussion centered around identifying where the contact matching process may be occurring and validating whether translation or field-mapping logic could be contributing to the issue.

 

Community Insights

  • One attendee asked whether browser- or operating-system-level translation tools could be leveraged instead of maintaining translated labels directly within the form experience.
  • Another recommendation was to test the form entirely in English and compare the results to determine whether the issue is related to translation, field mapping, or the flow logic itself.
  • If the behavior differs between languages, reviewing the flow's matching criteria and language-specific mappings may help identify the root cause.

Additional Resources & Reminders

We look forward to seeing you at the next session!

0/9000