Suggested answer

The accepted factors are the Salesforce Authenticator mobile app, third-party time-based one-time password authenticator apps, physical security keys, and built-in platform authenticators such as fingerprint or facial recognition on a laptop or phone.

The distinction candidates most often miss: email and SMS one-time codes are not accepted as a multi-factor factor. They are identity verification methods, used when someone logs in from an unrecognised browser or device, and both channels are susceptible to interception and account-takeover attacks. Proposing SMS as the second factor is a common way to fail a security review.

When single sign-on is in place, the cleanest design is to satisfy the requirement at the identity provider — it already has the enrolment, the recovery process, and the policy engine, and Salesforce trusts the authentication described in the assertion. If Salesforce is still challenging those users, I do not disable multi-factor authentication; I look at what is demanding a higher assurance level than the single sign-on login method has been credited with. I would also confirm the current accepted-method list in Salesforce Help, because that guidance is revised over time.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.