MFA - Getting Started
Welcome to the Customer Success Ohana! This group is dedicated to helping you get started with MFA, also known as Multi-Factor Authentication, and formerly known as Two-Factor Authentication or 2FA. Join the conversation here to ask questions, get answers, learn best practices, and share experiences as you continue your journey.
Join the ConversationRecent Posts
RENY RAJAN
According to Salesforce, if MFA has to be given to a specific user alone, we can use the permission set as mentioned here in https://help.salesforce.com/articleView?id=sf.mfa_direct_login_user_perm.htm&type=5. In my case, we have SSO enabled and I tried to just assign the permission set to one user and also made sure that in the Session Security Levels on Setup, the SSO configuration is in the Standard column and Multi-Factor Authentication is in the High Assurance column as per https://help.salesforce.com/articleView?id=sf.mfa_sso_logins.htm&type=5 But still with this, the user don't see a second level prompt to use the authenticator when the user logins. Does that mean that if SSO is already enabled, can we only make the changes to the profiles and not specific users and we really don't need to use the permission set ? Thanks. More
1 day ago · 2 comments · 0 likes
Tammy Rahn
As you begin to plan for MFA, check out the MFA Rollout Pack. This pack provides customizable planning and change management templates (with guidance) to help you roll out MFA to your users. Key assets include: * MFA overview presentation * Sample project schedule * Sample drip email campaign * User training deck * User onboarding quick guides You can download the pack here: https://sfdc.co/download-mfa-rollout-pack. More
2 days ago · 0 comments · 1 likes
Chris Feldhacker
When performing MFA through an SSO identity provider, some configurations allow MFA to be bypassed when the login originates from a trusted network and device; in all other case, MFA is required. Do such "hybrid" SSO-MFA configurations meet the Salesforce MFA requirement, or does Salesforce require an "MFA always" configuration? More
3 days ago · 0 comments · 3 likes
Chris Feldhacker
MFA FAQ says "Automated Testing Account Logins to the UI" and "API / Integration Logins" do NOT require MFA. Elsewhere, in the section about how will Salesforce enforce MFA it says: "On a rolling basis starting in February 2022, we will begin automatically enabling MFA for users who log in directly to your Salesforce products." How will Salesforce determine if a user is a "automated testing" user or an "integration" user so that they do NOT have MFA enforced? More
6 days ago · 0 comments · 5 likes
Chris Feldhacker
Do SFDX "scratch" org require MFA? The documentation calls out various sandbox and org types, but scratch orgs are not mentioned at all. More
6 days ago · 0 comments · 3 likes
Talking About...
MFA · MFA Webinar · SSO · Salesforce · Security · MCMFAWebinar · Salesforce Authenticator · Salesforce MFA · CommUpdates · DefenseInDepth

