Skip to main content

#MFA16 人正在讨论

Hi everyone,

I have an issue with 3 new users in our Salesforce org.

They replaced former employees, and I reused the former employees' Salesforce User records instead of creating new Users. I changed the name and username.

The users are Active and not Frozen, but they cannot complete the login process normally.

As an admin, I can generate a Temporary Verification Code. They can log in with it and reach the QR code screen to set up MFA, but I’m wondering if the previous user's MFA/verification method could still be linked to the User record.

Is there an official way to disconnect the previous user's MFA/verification method and register a new one for the new user?

Also, could this be related to any Summer ’26 MFA/authentication changes?

Would it be better practice to deactivate the old User and create a completely new User for each new employee?

Thanks for any advice!

And sorry for my English — I’m French 😊 

 

#MFA

8 个回答
0/9000

Hi, 

We setup the Tableau Server 2026 with Local authentication, and in the process of hosting the site externally, for security reasons, we need to have MFA for the login process. I don't see an option for MFA. This project is for external customers, who are not in our domain, and will not be added to the domain. 

 

What options do we have for MFA or any additional security options than just username + password. 

 

#Tableau Server  #MFA

2 个回答
  1. 9月1日 19:36

    Just an additional comment on the Identity Pool part as it is easy to mix up things. 

    Identity Pool is a pair of 1) an identity store and 2) an identity provider. 

    identity store can be local or AD/LDAD, and identity provider always and only OIDC. 

    But the Identity Pool identity store is constrained by your original identity store defined during Tableau Server installation. 

    If identity store local then Identity Pool identity store can only be local (same or new) 

    If identity store AD/LDAP then Identity Pool identity store can be AD/LDAP (but the same!) or local.

    It is pretty cool but tedious to configure as there is no tsm command or GUI to configure it. it is all through REST API calls only. 

    Then your Tableau login page will have an additional button, for example External users. 

    The internal users can continue to use Local authentication or SAML, it is totally independant.

    Just an additional comment on the Identity Pool part as it is easy to mix up things. Identity Pool is a pair of 1) an identity store and 2) an identity provider.

    It was a very good idea from Tableau, but Tableau didn't further develop this feature since 3 years. 

0/9000

Hey Folks, 

 

We have a couple of contractors that are having issues creating passkeys for the upcoming phishing resistant mfa for privileged users update. Thus far, all the regular employees using company issues devices are having having any problems. For these two, one uses a mac and the other uses a virtual windows machine. Because of this, we believe this may be the problem. Does anyone have any experience creating passkeys with these cases? 

 

#Security  #MFA  #PhishingResistantMFA

2 个回答
  1. 9月1日 13:20

    For anyone with this same question - SF support has stated that virtual machines are exempt from this requirement. We did observe this as I was prompted to create a passkey when logging into the environment but the user with the VM was not prompted when they logged in to the same env.

0/9000

I'm running into two issues and hoping someone can point me in the right direction.

 

Issue 1: MFA Temporary Verification Code A user has switched to a new laptop and doesn't currently have Windows Hello or another built-in authenticator configured. As a System Administrator, I attempted to generate a temporary verification code so they could log in, but received the error:

This occurs even though I'm already logged in as an admin and my device has a built-in authenticator available.

Troubleshooting already attempted:

  • Confirmed MFA is configured under Session Security Levels.
  • Temporarily adjusted MFA-related session security settings and retested.
  • Cleared browser cache/cookies.
  • Tested in both Chrome and Edge.
  • Verified active administrator session and attempted identity re-verification.
  • Same error persists.

Issue 2: Unable to Log a Salesforce Support Case I then attempted to log a Salesforce Support Case via Salesforce Help, but I don't have a "New Case"

option available anywhere in the support portal.  

 

Has anyone encountered either of these issues before?

  • Is there a prerequisite for generating temporary MFA verification codes that I might be missing?
  • Are there specific permissions or support entitlements required before the "New Case" option appears in Salesforce Help?

Any advice would be greatly appreciated. Thanks! 

 

#MFA

5 个回答
  1. 8月20日 04:25

    Hi @Katrina Luck

      

     I investigated this a bit further, and I believe the issue is most likely related to the fact that the Salesforce Setup interface runs on a different domain (my.salesforce-setup.com), while the org itself runs on my.salesforce.com. Combined with the recent passkey/MFA security changes, this appears to cause the problem.

    Fortunately, there is a simple workaround. Switch to Salesforce Classic and access the Connected App from there. In Classic, Setup is not redirected to the my.salesforce-setup.com domain, and the passkey verification works as expected, allowing you to reveal the Consumer Secret.

    We have also opened a Salesforce support case, as this appears to be an issue specific to the Lightning Setup experience.  

     

    https://trailhead.salesforce.com/trailblazer-community/feed/0D5KX00000jAN1h0AG

0/9000

Hello All, 

We are currently facing an issue with the Salesforce Connector for Google Sheets. We have been unable to export Salesforce reports to Google Sheets using the connector. 

We are receiving the following error message: 

"In order to get all of the report data, disconnect and re-authorize the Add-on from Salesforce using Help > Connection Information > Disconnect Add-on. Once disconnected, log in to Salesforce again using the Add-on." 

Based on our initial findings, we suspect that this issue may have been caused by the recent MFA enforcement in the Production environment.  

Each time a user tries to export a report, a new verification window opens and asks for an MFA verification code.

We are using the Salesforce Connector and have followed the instructions provided in the error message. After reconnecting, the export works only up to 2,000 records, and then the connection fails again.

Is there any workaround or recommended solution to prevent repeated MFA prompts and allow users to export reports successfully?

 

 

 

#Salesforce Admin  #Security  #MFA  #Salesforce_connector

5 条评论
  1. 8月14日 12:03

    I met with Salesforce support. The option given to me was to suspend the MFA security changes from last month for 90 days. It was implied that google was aware of the issue and that it would likely be resolved before the 90 days was up.

0/9000

*** Important updates: MFA Enforcement Update: R1 Window Rescheduled to July 27-28 ****** Important updates: MFA Enforcement Update: R1 Window Rescheduled to July 27-28 ***We wanted to give you a heads-up that the R1 MFA enforcement window has been updated.We wanted to give you a heads-up that the R1 MFA enforcement window has been updated. Here's what you need to know:

 

What Changed

The R1 enforcement window has moved from July 21–22 to July 27–28.

 

Why the Change

We made this adjustment to address a few things:

  • Additional time was needed to fully process previously approved extensions
  • Some SSO users on orgs with approved extensions were being unexpectedly prompted for MFA

If You Have an Approved Extension

Keep in mind that approved extensions can take up to 48 hours to take effect, so you may still see MFA prompts during that window.

 

If your org has an approved extension but you're still being prompted for a passkey, please refer to this Knowledge Article for detailed guidance on specific use cases.

 

What's Not Changing

  • The MFA for All schedule remains the same
  • R2a, R2b, Japan & Korea, and all subsequent release groups are on their original schedules

Where to Find the Latest Info

The PRMFA Knowledge Article has been updated to reflect the new R1 window — that's your best source for the current schedule and details.

 

Have questions? Drop them in the comments below and we'll do our best to help! 

 

#MFA #Security

2 条评论
0/9000
26 条评论
  1. 7月7日 07:21

    good 

     

0/9000

While the intent behind Salesforce’s step-up authentication framework is both understandable and necessary given the increasing sophistication of data exfiltration risks, the current implementation introduces meaningful friction into core user workflows—particularly around reports and dashboards, which are among the most frequently accessed features for our business teams. 

 

From an adoption and usability standpoint, this experience is suboptimal. Requiring users to re-authenticate at the point of simply

viewing or running

a report—potentially multiple times per day—creates interruption in critical workflows, slows down data access, and adds cognitive and operational overhead. This is especially impactful in environments like ours where we are actively driving Salesforce adoption, encouraging teams to replace offline trackers, and reinforcing Salesforce as the single source of truth. 

There is a real risk that this added friction could inadvertently push users back toward less secure, manual alternatives (e.g., screenshots, exported files stored locally, or shadow tracking), which ultimately undermines both the adoption goals and the spirit of the security control itself. 

While the security objective is valid, the user experience could be significantly improved with more thoughtful enablement patterns and modern authentication approaches. Guidance that I would have assumed be offered by Salesforce themselves. 

For example:

  • Seamless, low-friction verification methods such as push-based approvals (e.g., Salesforce Authenticator prompts) should be the default and strongly encouraged over email/SMS OTP, which are slower and more disruptive.
  • Biometric-based authentication (Face ID, Touch ID) and passkey/passwordless experiences should be positioned as the primary path to reduce user effort during step-up challenges.
  • Clear guidance and best practices from Salesforce on how to configure session policies (e.g., optimal step-up intervals by role/use case) would help organizations strike the right balance between security and usability.
  • Proactive end-user enablement (tooltips, in-product guidance, and admin playbooks) would ensure users understand why the prompt is happening and how to complete it quickly.

Ultimately, achieving the right balance between security and usability

is critical. If step-up authentication becomes too intrusive, it risks becoming a barrier to productivity and platform adoption—particularly for high-frequency report users. 

A more user-centric approach—leveraging modern, fast, and intuitive authentication methods combined with stronger guidance for Salesforce—would help ensure this change enhances security

without compromising the momentum on we're making on adoption and workflow efficiency

 

Any suggestions?  

 

#MFA  #Security

0/9000
1 条评论
  1. 5月24日 19:15

    Thank you @Michael Kolodner for the (as always) great article. The lack of clarity around whether 1password style cloud-passkeys will work or not is incredibly frustrating. With small nonprofits, they're in budgeting season so having to allocate precious funds to 1 or 2 new licenses in order to have broad coverage from a consulting partner is not going to go well, especially because it gets them right back to where they were (broad coverage support from partners) that they were before. And you're right, this is not winning any hearts and minds and partners supporting small np's are all pretty confused about what to tell our clients.

0/9000

I'm reviewing and trying to be prepared for the security roadmap enforcement dates.  We have a Marketing Cloud integration that was set up in 2021 by (with) an integration partner and a Salesforce Senior Manager (Solution Architect).  We have a dedicated license for the integration user, and it's set up as a System Admin at their direction.  From what I understand, API-only is not an option for MC Connector integration. There hasn't been a UI login for that user since 2021 when it was created.  It is not set up for MFA (not specifically exempted at this time, also not actively required either).  I'm trying to figure out whether the new requirements are going to break that integration when the mandatory enforcement begins.  I'd rather not touch it unless I have no choice - disruptions during our peak busy season are extremely unpopular.  Could use some clear, specific guidance.  Thank you! 

 

#MFA  #Marketing Cloud

1 个回答
  1. 5月16日 01:40

    Based on Salesforce official documentation, I would separate this into two topics:

    1. MFA is required for human or interactive logins. Marketing Cloud Engagement documentation states that MFA is required for users accessing the platform directly.
    2. Salesforce also documents that MFA isn’t required for system integration login types via API. However, if an admin or anyone else logs in interactively as that integration user, MFA is required for that login.

    For Marketing Cloud Connect specifically, the Salesforce Integration User License / API Only System Integrations profile is not compatible with Marketing Cloud Connect, according to Salesforce documentation. So the “API-only user” approach is not the right path for this connector.

    My interpretation is: if the user is only being used by the Marketing Cloud Connect integration/API flow and no one logs in interactively with it, MFA should not break the API integration based on the current documentation. But because the user is a System Administrator, and Salesforce is enforcing stronger MFA requirements for privileged users, I would confirm this with Salesforce Support before the enforcement date and make sure MFA is registered in case the user ever needs an interactive login for maintenance, reconnecting, or refreshing credentials.

     

     

    https://help.salesforce.com/s/articleView?id=mktg.mc_overview_mfa.htm&type=5

0/9000