Skip to main content

#Identity and Access Management2 discussing

A Salesforce Certified Identity and Access Management Specialist assesses the architecture environment and requirements; and designs sound and scalable technical solutions on the Force.com that meet the Single Sign on (SSO) requirements.

Today I have facing an issue, In my project we have some developer sandboxes. After sandbox refresh action completed, Currently we are unable to verify the email for the non admin users (users whom are not mentioned in the public group which can mentioned during sandbox refresh process). Means, Once sandbox refresh done, We unfreeze the active user and update his original email and that user have received the verification email with verification link. But during clicking the verification link, it's required login to confirm the email address. 

 

But you know, That user doesn't able to login into salesforce because the sandbox just refreshed and user doesn't have the access for the org, We actually ask the user to confirm the email for perform the "password reset" action for that user to enable the access for the org. 

 

So how to by pass this "Login required" behaviour and verify the email link as like previous from the email directly? 

 

Even I have disabled the Permission "

Require identity verification for email address changes" from Identity Verification settings as per Salesforce docs.

 

But still the behaviour is same, So anyone know how to fix/bypass this? 

 

Any help appriciated. 

 

#Salesforce Admin #Sandboxes #Security #Identity and Access Management #Salesforce

 

Thanks, 

Mohanraj S 

 

 

1 answer
  1. Sep 22, 4:06 PM

    We have had luck in resolving this a few ways. 

    • Selecting the 'Generate new password and notify user immediately' checkbox. 
    • Generating a temporary verification code and sending to them. 

    Otherwise you may need to reach out to Salesforce support to get help. There was a bug that says it has been fixed. Users are not able to change and verify their emails in all Orgs after Summer 26 release | Issue Details | Salesforce Help

     

     

    Either way, it also explains other options that may help unstuck your non admins in a Sandbox. 

0/9000

https://sforcemaximizer.com/mastering-salesforce-identity-and-access-management-architect-exam-a-practical-approach-to-exam-preparation-with-my-course/

If you are an admin, developer or architect looking to pass the Salesforce Identity Access Management exam, my blog will provide you the details of a course which I recently authored in Salesforce Ben and help you pass the exam. This is a tough exam due to lack of topic areas where there is not many opportunities to work and get experience on and hope my course helps folks on there journey to CTA!!

@SecurityForce @* Salesforce Administrators * @Admin Tricks@Manufacturing User Group@Higher Ed User Group, Northeast, US@Architect Group, Austin, TX US@Architect Group, Boston, US@Architect Group, Orlando, US@Architect Group, Columbus, OH, US@Architect Group, Los Angeles, US@Architect Group, London, UK@Architect Group, Chennai, IN

 

#Identity and Access Management  #Security

0/9000

Hello, I am preparing for the Identity and Access Management Architect credential.

 

Some time ago, before there was Experience Cloud, I would use either Customer Community and Customer Community Plus licenses for customers logging in to Customer Communities, or Partner Community licenses for partners logging in to Partner Communities.

 

Now we have 2 identity licenses - Identity Only and External Identity:

Salesforce Identity Licenses

 

Identity Only - A license for Salesforce employees (internal users) that want to use Salesforce for logging in to a service outside Salesforce. In this case that would be a user using Salesforce as Identity Provider, but using an external Service Provider app. Yes or no?

 

External Identity - A license for Salesforce consumers of your business, such as customers, prospective customers, patients, partners, and dealers (external users). I don't understand the purpose of this license. As I wrote above, customers and partners have had their own license for some time. Can anyone explain the reasoning behind this?

 

#Identity and Access Management #Technical Architect #Solution Architects #Experience Cloud

10 answers
0/9000

User provisioning question - what options do we have to sync user attribute data and provision users in Salesforce from an on-premise system that does not have any prebuilt connectors (like OKTA, AD etc) with no SSO (so no SAML JIT). Is it pretty much limited to using SOAP or REST callouts?

#User Provisioning #Identity and Access Management

1 answer
  1. Manoj Nambirajan (Dell Technologies) Forum Ambassador
    Jul 11, 2022, 12:15 PM

    yes.. dont see any other option. Could potentially be a webservice call out (soap or rest api) which compares user existence in SFDC while comparing with on-prem system and create user accordingly.

0/9000

I am looking at the documentation for IdP and SP initiated SAML and seem to come across conflicting information if the IdP-initiated SAML supports deep linking. From what I understand, myDomain is required for deep linking in both cases (though generally optional for IdP-initiated SAML) and the IdP must support the RelayState parameter, but then I see other posts saying that only SP-initiated SAML can support deep linking. So which one is correct?

#SAML Single Sign On #Deep Links #IdP Vs SP #Identity and Access Management

1 answer
0/9000

Is Salesforce's "OAuth 2.0 User-Agent Flow the same as OAuth Implicit Flow?  Salesforce documentation references OAuth 2.0 User-Agent Flow, but I can't find a reference to this name in any non-Salesforce documentation.  From reading the description of the flow, it *almost* matches what other OAuth-related resources call Implicit Flow or Implicit Grant.  BUT, the Implicit Flow doesn't return a refresh token, while documentation for User-Agent Flow say that a refresh token is returned.  Furthermore, non-Salesforce documents discourage the use of Implicit Flow and instead now recommend Authorization Code with PKCE as an alternative.  So what is this User-Agent flow and how does it map to the flows defined in the OAuth standard?

@Ladies Be Architects #Identity and Access Management #OAuth Flow #Security 

2 comments
  1. Feb 17, 2020, 1:41 PM

    Hi guys,

    Following up on this:

    We have a requirement to use PKCE for OAuth flows.

    Does Salesforce now support PKCE flows ? and if so where can we get access to docuemntation that illustrates how this can be configured.

    Kind Regards

0/9000

That SSO session was amazing - thanks so much to @Charly Deloitte Prinsloo  for taking us through it. Join us for an in-depth tour around SSO with SAML! We talk about federated authentication, IdP vs SP-initiated flows, SAML parameters and My Domain.

SSO & SAML Study Group - Oct 2018

1 comment
0/9000

Thank you to everybody who took part in @Natalya Murphy's Identity and Access Management study group:

 

John M. Daniel, Madhavi R., Harish Dintakurthi, Winnie Vu, Terry Miller, David Bergerson, Jeff Hunsaker, Svatka Simpson, Luz Paulina Chavez, Brenda Glasser, Amit Jain, Pavithra Vishwanath, Clara Pérez, Satish Penmethsa, Edith Valencia Martínez, Jaseem Pookandy, Igor Androsov and Joseph Thomas

 

And finally, to the lady herself, Natalya Murphy, who has given about 50 hours of her time this year to help others study towards this and the Integration Architecture exam this year. This is amazing content that will help people all over the world get certified in some of the most advanced areas of working with the hashtag#salesforce platform.

 

Thank you from the bottom of our hearts. We are really pleased to share the whole study group with you which can be found on YouTube. Don't forget to subscribe for more content :0)

Identity and Access Management Study Group

2 comments
  1. Dec 31, 2018, 11:26 PM
    @Natalya Murphy is fantastic! I appreciate all her efforts and the efforts of my fellow study partners. Great work all!
0/9000

Three more recordings available this week around #Identity and Access Management - thank you to @Natalya Murphy and ALL of her special guests for providing such great content to support others with this challenging exam

 

@Architect Trailblazers 

PLAYLIST: Identity & Access Management Study Group

1 comment
  1. Dec 3, 2018, 12:45 PM
    Thanks! This is my next exam and I will have System Architect! CTA in 2019 is my goal!
0/9000