Suggested answer

Salesforce assigns every login and verification method a session security level — typically Standard or High Assurance — and specific resources can require the higher level. If a user in a Standard session reaches a resource that requires High Assurance, they are prompted to step up rather than simply refused.

A design I have used: a connected app exposing a payments integration, and report folders containing regulated data, both set to require High Assurance, with the multi-factor login method raised to High Assurance in session settings. Day-to-day work is unaffected; the moment someone opens the sensitive resource, they are asked to verify. The profile setting that requires a session security level at login is the blunter alternative when a whole population must always be at the higher level.

The reason I reach for this rather than profiles and permission sets is that assurance is a property of this session, not of the user. Encoding it as a static assignment loses that, and cannot react to how the person actually authenticated today.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.