What multi-factor authentication methods does Salesforce accept, and how do you design MFA when SSO is in play?
Suggested answer
The accepted factors are the Salesforce Authenticator mobile app, third-party time-based one-time password authenticator apps, physical security keys, and built-in platform authenticators such as fingerprint or facial recognition on a laptop or phone.
The distinction candidates most often miss: email and SMS one-time codes are not accepted as a multi-factor factor. They are identity verification methods, used when someone logs in from an unrecognised browser or device, and both channels are susceptible to interception and account-takeover attacks. Proposing SMS as the second factor is a common way to fail a security review.
When single sign-on is in place, the cleanest design is to satisfy the requirement at the identity provider — it already has the enrolment, the recovery process, and the policy engine, and Salesforce trusts the authentication described in the assertion. If Salesforce is still challenging those users, I do not disable multi-factor authentication; I look at what is demanding a higher assurance level than the single sign-on login method has been credited with. I would also confirm the current accepted-method list in Salesforce Help, because that guidance is revised over time.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.