Skip to main content
Group

SecurityForce

Security is a team sport -- This is a collective of Salesforce and Security practitioners working on building a secure Salesforce ecosystem.

Hello Trailblazers,

I am facing a login loop issue with a System Administrator profile when trying to access the Salesforce Mobile App on an iOS device (iPhone), and I would appreciate your insights.

 

  1. I can log in into the desktop version perfectly using Windows Hello PIN as a registered Built-In Authenticator (Passkey).
  2. When trying to log into the Salesforce Mobile App on iOS, after entering the Username and Password, the app forces a Passkey verification.
  3. The native iOS is still prompting me to use a passkey and there is no chance to choose another verification option. Since the passkey was created locally via Windows Hello, the iPhone cannot resolve it, leading to a dead-end with no option to bypass or cancel.

What I tried so far:

  • I disconnected the Built-In Authenticator from the User's Advanced Details via desktop Setup.
  • Upon trying to log in again on the mobile app, it bypasses the old key but immediately demands the creation of a new Passkey.
  • If I attempt to use a Temporary Verification Code, the login attempt is blocked beforehand by the following error message: 

    "Problem Verifying Your Identity. To log in, you need both a higher access level and an identity verification method. Contact your administrator to gain login access."

Context & Constraints:

  • This is a production environment, so I cannot modify global organization settings (such as changing Session Security Levels or altering My Domain mobile browser behaviors) without a formal change control process. I need a solution targeted either at the user level or understanding why the Mobile API triggers this specific high-assurance restriction for this profile.

 

Has anyone encountered this specific behavior where the Mobile App demands a High Assurance MFA method that blocks the login completely before allowing alternative verification? Any workarounds at the user/permission set level would be highly appreciated.

Thank you in advance! 

 

@Salesforce Administrators & Developers, @Salesforce Administrators and Developers, @APAC Architects, @Data Quality & Management, @SecurityForce

 

 

#Trailhead Challenges  #Salesforce Developer  #Salesforce Admin

3 answers
0/9000

Hello, We recently ran a Health Check and one of the items in there was to turn on - Require HttpOnly attribute. I read a lot of documentation and other available blogs that state 99% of the time it should be good to enable it. Obviously we would do that in a full sandbox and test things out, but I wanted to ask folks here if there are any known issues or caveats we should be aware of and look for them first. We have a ton of managed packages in the organization.  

 

Thank you so much! 

4 answers
  1. Apr 20, 10:49 PM

    The Developer Console is not available if the Require HttpOnly attribute is selected.  That is the main drawback.  Some VisualForce pages rely on Javascript getting the session token from the cookie and this will also fail. 

     

0/9000

Regarding Spring '26 "Authorized Email Domains" security enhancements., Salesforce indicates exceptions for gmail.com and outlook.com domains. My University runs our email on Outlook servers, but our domain name is that of the University. Does the exception by Salesforce apply to Outlook servers regardless of domain name, or only for outlook.com

as the domain? 

Thank you!

1 answer
  1. Mar 30, 5:28 PM

    Great question regarding the Spring '26 Authorized Email Domains security enhancement. Here's the clarification:

    The exception is domain-specific, not server-based.

    Salesforce's exceptions for gmail.com and outlook.com apply to those specific domains, not to all mail servers that happen to use the underlying infrastructure. This means:

    1. If your university email is sent through servers hosted on Microsoft 365 (Exchange Online) but the sender domain is youruniversity.edu, that does NOT automatically qualify under the outlook.com

    exception. 

    2. The exception applies only when the sender's email address domain is literally

    outlook.com, hotmail.com, or other Microsoft consumer email domains — not institutional domains using Microsoft infrastructure.

    What this means for your University:

     

    Your university's email domain (e.g.,

    unc.edu) will need to be explicitly added to the Authorized Email Domains list in Salesforce Setup to avoid disruption after the Spring '26 enforcement date.

    Action required:

     

    1. Go to Setup [right arrow] Email [right arrow] Authorized Email Domains (or "Organization-Wide Email Addresses" depending on release). 

    2. Add your university's email domain(s) to the authorized list. 

    3. Review the full release notes at the link you referenced to confirm the exact enforcement date and any additional exceptions.

    If you're unsure whether your domain qualifies, contacting Salesforce Support to confirm is the safest approach.

0/9000

I am not sure if this is the group to ask or not, but I work for a Nonprofit and while reviewing the Login History for the past 6 months, I noticed that a user who has been inactive since 2016, appeared to try to log into their SF account.  The login failed as the user is inactive, however, my question is more around would this be an attempt of someone getting a hold of an old email, username, password, etc and using this to try and login to our SF instance?  I do know it was from a Mac, it was Chrome and the IP address is from Clevland (or appears to be) and we are in Cincinnati.  Anyway, I am trying to determine if I should be concerned or note. 

 

#Security #Nonprofit

4 answers
  1. Feb 24, 9:31 PM

    Hi @Heath Parks

    , i hope you should not as If the user is inactive and the login shows “Failed – User is inactive”, then No access was granted ,No password was validated No data was exposed. 

     

    This is usually one of three things:

    • A bot trying old leaked credentials
    • Someone testing an old saved password
    • Random automated login attempt

    You’d only worry if you see: Multiple attempts , Attempts across several users and Successful logins 

     

    Hope that helps  

     

    Thank you

0/9000

https://invite.salesforce.com/eventmonitoringforsecurityintel?utm_campaign=uki_cbaw&utm

[…]t-1768993355&utm_medium=organic_social&utm_source=linkedin 

 

This 60-minute webinar will equip you with the knowledge to leverage Event Monitoring for superior security intelligence. Over 50 minutes, we will cover four critical areas: We begin with an Introduction to Event Monitoring, outlining the standard audit trail capabilities and clearly differentiating between active security monitoring and passive compliance logging. Next, we delve into Event Types & Data Model, examining crucial events like logins, API usage, and data exports, discussing the differences between real-time and historical event data, and breaking down the structure of the Event Log Files . The in-depth Implementation & Configuration section guides you through enabling Event Monitoring, setting up custom event log retention policies, and establishing seamless integration with your existing SIEM (Security Information and Event Management) platforms. We conclude by exploring practical Security Use Cases, demonstrating how to detect anomalous user behavior, build specific compliance reporting scenarios, and integrate event data into your incident response workflows.

0/9000
0/9000

https://sforcemaximizer.com/how-to-secure-your-agents-data-at-dreamforce-2025-for-admins-and-architects/

 

If you're an admin, architect, or IT leader who's eager to secure your Agents and learn practical best practices at Dreamforce 2025, check out this wonderful blog by

@Rachel Beard showcasing her hands-on session at Dreamforce this year. It’s a fantastic resource to help you prevent risks and confidently address questions from your CISO and compliance teams. @Admin Tricks@Admin Group, Philadelphia, US@Admin Group, Mount Laurel, US@Admin Group, Columbia, MD, US@Admin Group, Raleigh, US@Marketer Group, Philadelphia, US@Architect Group, Atlanta, US@Architect Group, Atlanta, US@Architect Group, Chicago, US@Architect Group, Chennai, IN@Admin Addicts@SecurityForce@The Blog Group

0/9000

My company was planning to implement API Access Control. After enabling it we have ran into couple issues. Latest is that the "Is single sign-on enabled" permission has disappeared. We haven't used delegated SSO in a long time so it doesn't impact the SSO as such but we have kept is permission enabled for end user profiles to prevent password resets. Is there another way to prevent password resets for users based on profiles? For admins and some special cases we still want to have passwords so we can't disable password login on the org level. 

 

Why can't these impacts be documented? It is really frustrating to discover these on trial and error basis. Like that also SOAP connections are impacted and apparently those cannot be authorized but you'd need to give "Use any API client" permission for the concerned user.

4 answers
  1. Sep 9, 2025, 7:43 AM

    You are right actually, it is not enabling of API Access Control that had made the "Is Single Sign-on Enabled" permission to disappear but disabling of the "Disable login with Salesforce credentials". Someone who shouldn't had done this without asking/informing and coincidentally at the same time as we were testing API Access Control.

0/9000

Consider the specific recommendations in this article to improve the security posture of your org in light of the ongoing social engineering threats: 

 

Protect Against the Salesforce Data Loader Related Security Threats

0/9000