『How Can Admins Reduce MFA Friction in Salesforce?』のカバーアート

How Can Admins Reduce MFA Friction in Salesforce?

How Can Admins Reduce MFA Friction in Salesforce?

無料で聴く

ポッドキャストの詳細を見る
Today on the Salesforce Admins Podcast, we talk to Jay Hurst, Senior Vice President of Product Management, and James Ferguson, Senior Director of Product Management, at Salesforce. Join us as we chat about MFA step-up authentication and what it means for Salesforce Admins. You should subscribe for the full episode, but here are a few takeaways from our conversation with Jay Hurst and James Ferguson. Step-up authentication protects sensitive actions Starting next week, Salesforce is requiring all users to use Multi-Factor Authentication (MFA). If you're a privileged user like, for example, an admin, you'll need to use a phishing-resistant MFA. That's why I sat down with Jay Hurst, VP of Product Management, and James Ferguson, Senior Director of Product Management, to talk about why these changes are vital to protect your org's data. The first thing to know is that AI is making it easier than ever to launch targeted phishing attacks at scale. So while the MFA requirements provide a good first layer of protection, we want to make extra sure you are who you say you are before you're allowed to perform certain actions, like downloading a large number of records or running a big report. Phishing-resistant MFA uses a passkey, like a fingerprint or facial recognition biometric, to verify that it's actually you and not just someone with access to your email account. Balancing security with user friction As Jay and James acknowledge, these changes will add some friction to your users' experience. However, with the pace at which these kinds of attacks are evolving, it's more important than ever to get serious about your security posture. "We're trying to introduce a little more friction right now so that people start to think," Jay explains, "and start to build those habits of understanding when they're doing something that potentially could be considered a malicious attack, such as downloading that All Opportunities report." They're also building out compensating controls that should make things easier in the future, allowing you to trust users from a certain IP range, for example. Security is a journey, not a destination The most important thing to realize is that these requirements are about more than just jumping through some extra hoops. Phishing and man-in-the-middle attacks are growing more and more sophisticated, and you need better protections than "Well, that hasn't happened yet." Instead, James and Jay recommend viewing this as an opportunity to partner with other stakeholders in your org to develop a comprehensive security plan. As Jay says, "Security is a journey, not a destination. What is 100% secure today is not as secure tomorrow." The trick is to develop a security-focused mindset throughout your business that will protect you now and in the future. Make sure to listen to my full conversation with Jay and James for more on step-up authentication and how admins can reduce friction for users. And make sure you're subscribed to the Salesforce Admins Podcast so you never miss an episode. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Admins Podcast Episode: What Are Security Essentials for Salesforce Admins? Salesforce Admins Blog Post: Securing Your Org: From Reactive to Proactive Salesforce Help Article: Prepare for the upcoming Step-up Authentication requirements on Report Actions Salesforce Help Article: Prepare for MFA Enforcement for All Employee Users Salesforce Help Article: Prepare for Phishing-Resistant MFA Enforcement for Privileged Users including Admins Salesforce Help Article: Security-Related Product Updates to the Salesforce Platform: User Identity, Data Protection, and Access Controls Admin Trailblazers Group Admin Trailblazers Community Group Social Jay on LinkedIn James on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: This week on the Salesforce Admins Podcast, we're talking with Jay Hurst and James Ferguson from Salesforce Product Management about MFA step-up authentication and what it means for Salesforce admins. As you know, security isn't just a front-door login decision anymore. It's about protecting sensitive actions, understanding risk, and designing systems users can trust. So Jay and James are going to help us unpack phishing-resistant MFA, compensating controls, IP ranges, SSO, and why these changes matter in a world where data, automation and AI are all working together. For us Salesforce admins, this is a chance to think beyond features and really look at how we steward the entire system. So listen in, click that Subscribe button, and of course I would love if you could share it with fellow Salesforce admins or, hey, you know what? Let's make some friends in that security team. So with that, let's get Jay and James on the podcast. So Jay and James, welcome to the podcast. Jay Hurst: Thanks for having us, Mike. James Ferguson...
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません