Skip to main content

When performing MFA through an SSO identity provider, some configurations allow MFA to be bypassed when the login originates from a trusted network and device; in all other case, MFA is required. 

Do such "hybrid" SSO-MFA configurations meet the Salesforce MFA requirement, or does Salesforce require an "MFA always" configuration?

3 条评论
  1. 2021年6月16日 06:36

    Using SSO has already huge security benefits compared to the direct login in Salesforce. So when using SSO it should be up to the companies themselves to decide if MFA is required on every login or not (like only MFA when outside trusted network). The Salesforce MFA requirement needs us to change our SSO setup.

    @Suzanne Zaleski

    . 2 questions:

    Can you please explain why Salesforce is requiring MFA also when using SSO (since SSO is already much more secure).

    How will Salesforce technically check that SSO has used MFA.

0/9000