Suggested answer

MFA enforcement options:

1. Auto-Enable MFA: Salesforce has auto-enabled MFA for all production orgs as of 2023. This requires all users to register a verification method (Salesforce Authenticator app, TOTP authenticator, security keys, or built-in authenticators).
2. Profile-level enforcement: Enable the "Multi-Factor Authentication for User Interface Logins" permission in a profile or permission set for selective enforcement.
3. SSO: If using SSO, MFA should be enforced at the identity provider level — Salesforce's MFA requirement then delegates to the IdP.
4. High-Assurance Sessions: Require MFA re-verification for specific sensitive actions (custom permissions, login flows). Admins can monitor MFA adoption via identity verification history reports.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.