Skip to main content

#Security185 discussing

Hi everyone,   

I have a question regarding the upcoming MFA enforcement for all employee users.   

Let's consider this scenario:

If organization has five administrators who all use the same System Administrator username and password (shared login). The email address associated with that Salesforce user belongs to me.

When Salesforce prompts us to register a Passkey, I complete the registration using my device because the email is mine. After that, when another administrator tries to log in using the same shared credentials, Salesforce requires the registered passkey, which only I have. As a result, the other admins are unable to log in.    How should organizations handle this situation?

  • Is sharing one System Administrator account no longer supported with passkeys?
  • Does Salesforce expect every administrator to have their own individual user account?
  • If a shared admin account must be used (for legacy reasons), what is the recommended approach to satisfy the new MFA/passkey requirement?

I'd appreciate any guidance or best practices from the community. Thanks!    

4 answers
  1. Aug 14, 11:15 AM

    Hi Sourabh, 

     

    Though sharing one admin account not supported using passkey, Salesforce also have ways to bypass this validation. 

     

    Method 1: Temporary Verification Code

    Steps to Generate a Temporary Verification Code

    Step 1 : Go to the User record and click the Generate link next to Temporary Verification Code (expires in 1 to 24 hours).

    Step 2 : Specify the number of hours for which the verification code should remain valid.

    This is one method of bypassing passkeys.

     

    Method 2: Salesforce CLI Authentication (VS Code needed) 

     

    https://www.aintiram.com/blog-bypass-pass-key-salesforce-authentication

     

     

    Both methods are explained in this blog, do check.

0/9000

Hi Team,

I have a requirement to hide those SKUs from the PDP if they have not been assigned a price book.

If it is a master, show only those SKUs with a price book.

If it is an SKU, we will show the 404 page as required.

 

#Security  #SFCC  #SFCC-SFMC Integration  #SFCC Administrator  #Sfcc-introductions  #Sfcc-ask-salesforce

3 answers
  1. Aug 17, 5:12 AM

    Hi @iqbal,

    Which architecture in SFCC js controller or pipeline So based on that I can suggest it.

0/9000

Hi everyone,  

 

I was wondering if anyone has experience adding multiple passkeys to the same user account.  

I have set up on key already with the password manager, but am trying to set up a second one on the phone only. The issue is the second attempt will say no matching passkeys found as it is already searching for existing.  

 

Alternatively, is it possbile to keep the passkey setup with the password manager, and add  a second physical security key in addition, and have the option to use either one of them? 

 

Thanks for the help!  

 

Marie Olsen 

 

#Login Attempt  #Multi-Factor-Authentication  #Security

2 answers
  1. Aug 15, 7:47 PM

    Hi Marie - yes, Salesforce supports registering more than one passkey/security key on the same account, and you can use any of them to log in. The behavior you're hitting is the classic passkey gotcha: adding a second one has to be done from the registration flow in your settings, not from the login screen. 

     

    Here's what's happening: at the login prompt, the browser/OS is trying to authenticate, so it searches for an existing passkey - that's the 'no matching passkeys found / searching for existing' message. That flow only looks for credentials already registered; it will never create a new one. So the second passkey has to be enrolled from inside your account. 

     

    To add another one: log in with your existing (password-manager) passkey, then go to your personal Settings and find the security-key / built-in-authenticator registration area (in Lightning it's under your personal Settings - look for Advanced User Details, which has the register links for a security key or built-in authenticator). Start the registration there, and when the passkey dialog appears, choose the new target - your phone, or 'use a different device' - rather than the saved password-manager one. That enrolls a second, independent credential. 

     

    On your alternative question: yes, you can absolutely keep the password-manager passkey and add a physical security key as well. Register the physical key the same way (from settings, not login), and at sign-in you can use whichever one you have on hand. Mixing a platform passkey with a roaming security key is exactly the kind of redundancy passkeys are meant to allow - having a backup method registered is a good idea. 

     

    One thing to watch: start each new registration from your account settings while you're already logged in, and pick the specific device when the OS dialog pops up - browsers love to default back to the passkey you already have. 

     

    Hope that gets your second one enrolled!

0/9000

Hello All, 

We are currently facing an issue with the Salesforce Connector for Google Sheets. We have been unable to export Salesforce reports to Google Sheets using the connector. 

We are receiving the following error message: 

"In order to get all of the report data, disconnect and re-authorize the Add-on from Salesforce using Help > Connection Information > Disconnect Add-on. Once disconnected, log in to Salesforce again using the Add-on." 

Based on our initial findings, we suspect that this issue may have been caused by the recent MFA enforcement in the Production environment.  

Each time a user tries to export a report, a new verification window opens and asks for an MFA verification code.

We are using the Salesforce Connector and have followed the instructions provided in the error message. After reconnecting, the export works only up to 2,000 records, and then the connection fails again.

Is there any workaround or recommended solution to prevent repeated MFA prompts and allow users to export reports successfully?

 

 

 

#Salesforce Admin  #Security  #MFA  #Salesforce_connector

5 comments
  1. Aug 14, 12:03 PM

    I met with Salesforce support. The option given to me was to suspend the MFA security changes from last month for 90 days. It was implied that google was aware of the issue and that it would likely be resolved before the 90 days was up.

0/9000

I am trying to create an External Client App in my oldest personal dev org (ca. 2013). When I attempt to obtain the client id and secret, I get an insufficient permissions error. My user has the standard System Administrator profile which is tied to the Salesforce license. When I search for the new External Client App permissions on the profile they are not there, so I created a custom perm set and gave it the permissions. Now when I try to assign the perm set I get:    The user license doesn't allow the permission: View External Client App Consumer Secrets in Metadata    Any ideas on how to resolve or workaround this?    

5 answers
  1. Aug 13, 12:45 PM

    Is there any update on this issue?

0/9000

Hello Trailblazers, 

 

I've recently run into a frustrating issue with Salesforce's mandatory Lightning Login Enrollment feature. I had signed up for this verification method and was able to log in successfully, but for the past couple of days, I haven't been able to log in. I keep getting the message:  

"To log in, you need both a higher access level and identity verification method. 

Contact your administrator to gain login access."

I'm not sure what's causing this. Please note that I've already tried clearing my browser cache and attempting to log in from a different browser, but with no luck. I was able to log in before using Salesforce Authenticator as my verification method. Now, every time I try to re-register on Salesforce Authenticator, I get the same message.

Has anyone faced a similar issue?  

2 answers
  1. Aug 13, 12:27 PM

    I've just "sorted" this issue with one of our users. The problem is that the new passkeys are not compatible with the lightning login. You need to disable this for the user: 

    I've just

     

    If you lookup the Passkey/Security Key in the database it should show it's active in the slot above Lightning Login, but it's not, it's in a new space. You need to scroll all the way down to a "Built-in Authenticator" section.  

     

    image.png

     

     

    If for whatever reason a user needs to login on a new device they will need to delete the passkey from their current device and you will need to remove this from their profile and then when they login they will need to use their authenticator app to setup a new passkey on the new machine. It's a nightmare.

0/9000

Hi everyone, 

I'm experiencing an issue in a Salesforce Sandbox when trying to access: 

Setup → App Manager → View App → Manage Consumer Details 

 

When I click Manage Consumer Details, Salesforce opens the Verify Your Identity dialog, but the authentication immediately fails with the following error: 

There are no built-in authenticators available to this browser. 

Verify Your Identity fails with 'There are no built-in authenticators available to this browser' when opening Manage Consumer Details

 

Environment:

  • Salesforce Sandbox
  • Google Chrome

 

What I've already verified:

  • Touch ID is correctly registered as my authentication method.
  • Touch ID works correctly for other authentication requests.

 

From what I've investigated, it appears that the Verify Your Identity dialog may be rendered inside an internal iframe, and the browser is therefore unable to access the registered authenticator. 

 

Has anyone encountered this issue before? Is this a known Salesforce or Chrome limitation, or is there a configuration or workaround that resolves it? 

 

Any help or suggestions would be greatly appreciated. 

 

Thank you! 

 

 

 

#Security

9 answers
  1. Aug 12, 6:22 PM

    Completely unacceptable. Yet another bug open for months, but this time while there's a workaround it should be fixed with how expensive licenses are. This is authentication and security... no workarounds are valid.

0/9000

Hello,       I am assuming a lot of people are having issues with the MFA regulations that have come up.       Has anyone found a workaround for multiple computers for one Salesforce account or Multiple users for one Salesforce account and the passkeys?       I am a System Admin with another person and we share a login, due to the client not wanting to purchase more licenses. She setup the passkey on her computer, but when prompted on my computer, I can not use the passkey option.       Has anyone found any solution or workaround?       Thank you. 

3 answers
  1. Aug 4, 1:51 PM

    You can register the passkey for one of the users from login screen and then get a temporary code generated from the user record page and try to login from the 2nd user's laptop using temporary code and add the passkey from the 2nd user system, this way you should be able to use single account for both.

    PS - I have not tried this myself I'm just suggesting this based on options I'm aware of in Salesforce.

0/9000

 Can anyone suggest why certain list views of Lead object are disappearing abruptly in my Salesforce production org multiple times? Each Time we are creating the disappeared list view and again they are disappearing.Any kind of suggestions are hearty welcome.

10 answers
  1. Aug 11, 4:45 PM

    Filters are fine, and there are multiple records under the view. I use/ show this filter link in the flow: Email alert. The user receives an email alert and can see the list view for one week or so, and then it magically disappears. Looks like a Salesforce bug to me.

0/9000

I want to understand what's the actual use case of Service Cloud License, so that I can evaluate how many license our org will require .  I checked without license,users from different  Profiles can see Service Console App, also cases can be assigned to them.

4 answers
  1. Aug 11, 1:10 AM

    thanks for your answer  @Steven Trumble

    , We don't have requirement of omnichannel and Einstein features etc. So If I have team of 20 people who will work on Case Management, Service Cloud User feature license need to be given to all? 

    Or if I give to few still, milestones, entitlelments etc. will work for all cases

0/9000