Skip to content

Not using MFA might be wrong for some users #618

@VinceFINET

Description

@VinceFINET

I am using OrgCheck (Nitrogen [N,7]) and discovered that the Security and Access > Active Internal Users tab is flagging many active users as not using MFA ("User is logging directly without MFA: This user is logging in directly to Salesforce without using MFA (Multi-Factor Authentication). And this user has not the MFA bypass enabled. Please work with your user to make them use MFA for better security.").

If I look at Setup > Identity > Identity Verification History, I see a different story!  Each of these users is being challenged with MFA and succeeding in logging in.  Their entries look something like this:

Triggered by: Multi-factor authentication requiredMethod: Salesforce AuthenticatorStatus: User challenged; waiting for response >> Succeeded

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions