Salesforce MFA
Photo by Firmbee.com on Unsplash, Coming to you on February the 1st

Salesforce MFA

The Salesforce ecosystem is worried at the idea that MFA will be enforced on all orgs, on Tuesday, February the 1st 2022. "How to prepare all the users for this change", "What if the users aren't ready", "Is there a risk to block prod"? The tension is intense for those aware, those who don't know this is happening are still sleeping as usual. How to manage the change? This is the question this post is going to try and answer.

MFA vs. TLS 1.1

It looks to me that Salesforce learnt its lesson with the move to TLS 1.1. The move to MFA is not a turn-off/turn-on story anymore. It's more gradual, it's more of a legal commitment to your favourite vendor (Salesforce). So, as a result, there is more flexibility on the date choice, your environment specificities are taken into consideration and, in the end, you can speak and negotiate with your Salesforce AE! I would personally recommend all Salesforce customers to start the conversation ASAP with Salesforce and start planning if not already done. January is going to go very fast in this respect!

The Approach

So, whereas I was planning to give technical clues in this article and suggestions about the best ways to move to MFA I will stop there: engage with Salesforce and agree on a timeline and action plan to move to MFA.

At a high level you want to consider the users' populations you are dealing with:

  1. All non-SSO internal users: Setup MFA from the Salesforce setup pages.
  2. All SSO-internal users: Setup MFA from your SSO Identity Provider.
  3. All external users: Experience Cloud No need to enforce MFA at this time (Is MFA required for customer and partner Experience Cloud sites?).

Only platform based Clouds are working with the date of Tuesday, February the 1st 2022. Other Clouds (Marketing, FSL, etc...) follow the same principle but with a different calendar.

The Action Plan

No alt text provided for this image

A few words about these suggestions from Salesforce:

  1. Take this change seriously and put as many resources as can (Learn). Then tick the (security) box for a while and return to BAU.

I suggest focusing on Salesforce resources (hostname = *.salesforce.com)

  1. In "Evaluate" read "Test"! Don't expect a good outcome if you shoot beside the actual target. You do need to validate you understand 100% the upcoming change. Get on a sandbox ASAP...
  2. To "Prepare Users" you want to communicate with all of them. Don't underestimate this point. Users can be blocked just because they didn't understand and that would result in part of your CRM investment being thrown out!
  3. In "Implement" don't forget your own support team. The helpdesk must be fully aware of what's going on, be prepared for a surge of calls and know what to do.
  4. I would suggest "Launch" before the actual date suggested by either Salesforce or your AE. This way, you can do a roll-back if it comes down to it.

Useful Resources

If there is something to accept is that, albeit this MFA story is meant to be a big change, Salesforce is providing quite a few documentation about what going to happen. I suggest you (1) master the documentation first then (2) jump on a phone call with your AE and (3) express your feelings, concerns or otherwise.

The Salesforce AEs will be capable to help you out while staying compliant with your legal obligations...

Key Resources

Secondary Resources

Summary

MFA is a very important change that Salesforce is going to force on us. This technological change is meant to increase the level of protection of our orgs. So, as such, it's a good thing!

Having said that you need to come prepared and avoid any downside. Because of the legal implications, I would suggest you get in contact with your Salesforce AE and agree on the action plan (in writing). Read any content you may find on the web but favour Salesforce resources as there is a notion of commitment you will need to rely on.

Sara Morgan Nettles

Salesforce Developer at AmWins/Pluralsight Author

3 年

Great article Fabrice!

Tal Dahan ? ???

Bring them home - Salesforce Expert | 7x Salesforce certified

3 年

Hi. what about users that log in through Okta. from log in to the computer? is that enough? or we need MFA anyway?

要查看或添加评论,请登录

Fabrice Cathala的更多文章

  • Salesforce Anti-Patterns (2nd edition)

    Salesforce Anti-Patterns (2nd edition)

    A couple of weeks ago, I was lucky to be offered the opportunity to review the book Salesforce Anti-Patterns by Lars…

    6 条评论
  • Salesforce for Beginners, 2E

    Salesforce for Beginners, 2E

    I have been fortunate enough to review the second edition of this great book by Sharif Shaalan and Timothy Royer, and I…

    1 条评论
  • Salesforce and Open Source

    Salesforce and Open Source

    With the ecosystem growing up, there are more and more people joining from other backgrounds who are keen to reset…

    4 条评论
  • The Underrated Salesforce DE Org

    The Underrated Salesforce DE Org

    I've always wanted to put in writing how thankful I was for the Salesforce Developer Edition orgs to exist..

    6 条评论
  • Salesforce New Release Preview

    Salesforce New Release Preview

    Understanding the intricacies of Salesforce's New Release Preview process must be done if you are regularly shipping…

    10 条评论
  • Best Practices. Says Who?

    Best Practices. Says Who?

    I have engaged with many customers throughout my career, in various countries, and all were looking at benefiting from…

    6 条评论
  • Facing The Customer

    Facing The Customer

    I wrote these sets of rules in the past when I was facing stressful customer meetings with a disjointed team, possibly…

    7 条评论
  • It's all about the users!

    It's all about the users!

    Looking back at my time in the Salesforce ecosystem, I've read quite a lot of resources destined to the developers or…

    2 条评论
  • Learning From The Web

    Learning From The Web

    Nowadays it's commonplace to self teach yourself by navigating the web and getting quick and free access to the…

    8 条评论
  • The Evolution of Software as a Service

    The Evolution of Software as a Service

    Nowadays I feel like people take for granted Software as a Service. They do expect to get all bells and whistles from…

社区洞察

其他会员也浏览了