Navigation
  • SEARCH HERE
  • SOLUTIONS
    • Information Security Solutions
      • Enterprise Application Security Solutions in Asia
      • Network & Infrastructure Security Solutions
      • Zero Trust Security
      • Security Information and Event Management
      • Remote Monitoring & Management (RMM)
      • File Integrity Management
      • Systems Administration Tools
      • Data Loss Prevention
      • Data / Password Recovery
      • IT Management Solution Offering | Distributor in Asia
      • Identity and Access Management Solution Offering | Distributor in Asia
      • Employee Activity Monitoring (EAM)
      • Digital Forensic Investigation
    • Software Development Solutions
      • Integrated Development Environments
      • Development Components
        • UI Tools
        • Networking Components
        • Office Components
        • Barcode Components
        • Communication Components
      • Imaging Solutions
      • Software Localization
      • Release Automation & Management
      • eLearning Authoring Solutions
      • Charting Solutions
      • PDF Solutions
      • Reporting Solutions
      • Testing & QA
      • Text Retrieval / Enterprise Search
      • Database
  • Services
    • Live Solution Walkthroughs
    • Implementation Services
    • Best Practices Consulting
    • Pre-Sales and Post-Sales Services
  • What's New
    • Our Event
    • Our Blogs
    • Special Offers
  • About
    • About LOGON Software Asia
    • Our Partnership
  • Publishers - Join our network
  • Resellers - Expand your portfolio
  • Procurement Managers
Site logo
  • Solutions
    • Information Security Solutions
      • Identity and Access Management
        • Privileged Access Management (PAM)
        • Multi-Factor Authentication (MFA)
        • Identification Verification (IV)
        • Self-Service Password Reset (SSPR)
      • Network & Infrastructure Security
        • DDoS Mitigation and Protection
        • Digital Forensic Investigation
        • Malware Detection & Analysis
        • Network Monitoring Software
        • Email Security
        • Log Monitoring
      • Endpoint & Device Security
        • Patch Management
        • Remote Monitoring & Management (RMM)
        • Employee Activity Monitoring (EAM)
        • Mobile Device Management (MDM)
      • IT Management
        • IT Service Management
        • IT Asset Management
        • Software Asset Management
        • Hardware Asset Management
        • Software License Management
        • Systems Administration Tools
      • Application Security
        • Development Security | Shift Left AppSec | SAST, SCA, IAST
        • Runtime Protection Solutions | DAST, RASP, WAF, Container Security
        • Strategic Management Solutions | ASPM, MAST, VAPT
      • Data Security
        • Data / Password Recovery
        • File Integrity Management
        • Data Loss Prevention
      • Cloud Security
        • Cloud Security Posture Management
        • Cloud Work Protection
      • External Attack Surface Management
        • Cyber Threat Intelligence
        • Third Party Risk Management
      • Security Operations & Incident Management
        • Security Information and Event Management
        • Security Orchestration, Automation and Response (SOAR)
      • Zero Trust Security
    • Software Development Solutions
      • Integrated Development Environments
      • Imaging Solutions
      • UI Tools
      • Charting Solutions
      • Developer Tools
      • Database
      • Networking Components
      • Office Components
      • Barcode Components
      • Release Automation & Management
      • Software Localization
      • Communication Components
      • Automated Testing
      • eLearning Authoring Solutions
      • Reporting Solutions
      • Text Retrieval / Enterprise Search
      • Testing & QA
  • Services
        • Live Walkthrough Sessions

          Experience the full feature of our key solutions through live platform

          View All Sessions >
        • Implementation Services
        • Pre-Sales and Post-Sales Services
        • Best Practices Consulting
  • Partners
    • Our Partners
    • Partner with LOGON Today!
      • Vendors - Join Our Network
      • Resellers - Expand Your Portfolio
      • Procurement Managers
  • Resources
        • ABOUT US

        • About Us
        • Our Locations
        • Careers@LOGON - We are hiring !
        • DISCOVER

        • Our BlogsNEW BLOGS
        • Our EventsJOIN UPCOMING EVENTS
        • LOGON to CyberSecurity PodcastNEW EPISODES
        • GET HELP

        • Contact Us
        • Help Desk
        • Request a Demo
        • Request a Quote
        • COMPLIANCE

        • 🇭🇰 Hong Kong PDPO
        • 🇮🇳 India DPDP Act
        • 🇸🇬 Singapore PDPA
        • 🇹🇭 Thailand PDPA
  • More results...

View large
Blog, ISDecision Blog, UserLock

Meet Salesforce MFA Requirements via SSO With Active Directory Identities | IS Decisions

Meet Salesforce MFA Requirements via SSO With Active Directory Identities

This article was originally published by LOGON’s partner IS Decisions. Click here to view the original article.

In response to the global threat landscape, Salesforce now requires multi-factor authentication (MFA) for all logins. While Salesforce has enabled MFA on direct Salesforce logins, MFA is also a contractual requirement for users who access Salesforce products through a single sign-on (SSO) service. Here’s how to comply with the Salesforce MFA requirement, while providing secure access and easy adoption for your team.

 

How Can Active Directory Users Meet the Salesforce MFA Requirement?

Salesforce spells out a few ways all users, whether in an Active Directory environment or not, can meet the new MFA requirement:

  • Turn on MFA directly in your Salesforce products to protect direct logins
  • Enable MFA with your provider’s SSO service

 

What About Trusted Corporate Devices?

Salesforce also makes provisions for organizations that use trusted corporate devices. Now, on their own, trusted corporate devices with certificates issued by services like AD or Mobile Device Management (MDM) don’t meet Salesforce’s MFA requirement. And the reason why is simple: anyone who has access to the device can compromise and use these device certificates.

If you use device certificates for user access, you should turn on MFA for your SSO identity provider or your Salesforce products. If that’s not possible, you can satisfy the MFA requirement by meeting these two conditions for SSO or direct logins:

  • Your employees must log in from trusted corporate devices that have been issued a certificate, and
  • The trusted devices must be on an IP address in your corporate network’s IP range, either by accessing the network from inside the office or by using a VPN.

 

What MFA Solutions Are Best for Active Directory Users?

If you only want to apply MFA for Salesforce access, Salesforce’s native solution can be an option.

However, as Salesforce underlines, the increase in global threats makes MFA adoption a necessity – and adoption is well overdue for most companies. If you have any sensitive information at all on your company’s apps or network (spoiler: you do), it’s worth considering Salesforce’s requirement as an invitation to more broadly apply MFA to protect your Active Directory (AD) identities.

Before selecting a solution, you’ll want to make sure that your MFA solution builds on your existing AD infrastructure.

Then, you’ll want to choose the right type of MFA. Most organizations today opt for two-factor authentication (2FA), which requires two distinct authentication factors. It’s an optimal combination of increased login security, without being too burdensome to employees.

You can also choose between different authentication methods for the second step of 2FA. Among the most common methods are authentication apps like Google Authenticator or Microsoft Authenticator, and security keys, like YubiKey or Token2. Best of all, find an MFA solution that offers flexibility to choose different authentication methods.

As Salesforce emphasizes, “Driving adoption of strong MFA, the single best thing people and organizations can do to protect their user accounts and data, requires a range of MFA options, such as hardware keys.”

Of course, you don’t want your employees to lose time (and pull their hair out) with MFA for each and every app or service they access. That’s where combining MFA and SSO comes in.

 

Combine SSO and MFA Using Your Active Directory Login

With combined SSO and MFA, employees can log onto AD using their existing credentials and complete MFA just once to seamlessly access all line-of-business apps and cloud resources.

SSO eases MFA onboarding for your team, since it only adds one additional step to their access to network and cloud resources. It also makes teams more likely to stick with MFA, which is key. After all, the security methods we’re most likely to follow are the ones that are easiest to comply with.

 

Keep User Authentication On-Premises

For an on-premises AD environment, implementing SSO poses a unique challenge: how to safely transition to a hybrid AD environment. IT leaders at many on-premises AD organizations prefer, or are required, to keep user authentication on-premises.

But most SSO solutions on the market are cloud-based. So, to implement SSO in an on-premises AD setup, the first step is either to duplicate the on-premises AD user directory to the cloud, as is the case for SSO with Azure AD, or to create a new, separate directory altogether. This not only takes a lot of time to set up, but it can also become a nightmare to manage. Most importantly, sending user authentication off-premises increases the inherent security risks of SSO.

For optimal security, choose a secure SSO solution that uses your existing on-premises AD identities to keep user authentication safely on-premises.

 

Ease Adoption With Granular MFA

Granular access control offers organizations the ability to restrict or permit specific system access and control details on when and how MFA is prompted. The granular ability to force MFA for a specific cloud app like Salesforce can make it easier for your team to get used to MFA, requiring it now only for Salesforce access, and broadening it later on.

 

Choose Secure SSO With Granular MFA for Active Directory

Whether you’re looking for a better way to meet Salesforce’s MFA requirement, or simply want to apply MFA-enabled SSO, UserLock SSO provides frictionless access to cloud resources using your existing AD identities. Since it retains your on-premises AD for user authentication, SSO is secure, mitigating the risks on-premise AD environments encounter when shifting to a hybrid environment. And with granular MFA, you have full control over how often and under what circumstances to require MFA. So you choose the balance between security and productivity that’s right for your team.

User Logon Security for Windows Active Directory

Enable customized, two-factor authentication (2FA) on Windows logon, Remote Desktop (RDP & RD Gateway), IIS, VPN and Cloud Applications. Apply customized login restrictions by user, group or organizational unit (OU).

Solution Highlight

Get started with UserLock

Start a free trial with UserLock, with 30-day full version, no user limit, and free technical support.

Start Your Free Trial
Contact Us Today

FOLLOW US ON

  • LinkedIn
  • Facebook
  • Instagram
  • Twitter
  • YouTube
Read Next:
Application Security BlogArtificial IntelligenceBlogLOGON Blog
AI-Augmented Penetration Testing: Meeting the Scale Challenge
Application Security BlogArtificial IntelligenceBlogIT Management BlogLOGON Blog
The First Autonomous AI Cyber Attack is Here: Is Your Enterprise Ready?
Application Security BlogBlogLOGON Blog
Shift Left, Verify Right: The Blueprint for Modern Application Security Across Asia

Privacy Policy Company Overview

COMPANY

Our Location Career with LOGON Our Partners

SERVICES

Training Services Implementation Services Pre-Sales and Post-Sales Services Best Practices Consulting

GET IN TOUCH

Phone:
Hong Kong: +852 2512 8491
India: +91 70220 22744 / +91 63668 26133
Email: [email protected] ©2025 LOGON International Ltd. All rights reserved
logon logo WHITE

Search engine

Use this form to find things you need on this site

More results...

Fill in the form below
  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Watch On-demand Webinar

  • This field is for validation purposes and should be left unchanged.

Get Your Free UserLock Trial

  • This field is for validation purposes and should be left unchanged.

Download Your Free Trial 10-Day Trial Today

  • Downloading and evaluating Smart Package Studio is quick and easy
  • Includes a short introductory guide that suggests smart features to try
  • Access the full functionality of Smart Package Studio during the trial
  • This field is for validation purposes and should be left unchanged.

Request for Priority Support with our support team

  • This field is for validation purposes and should be left unchanged.
  • Drop files here or
    Max. file size: 30 MB.

    Get Free Assessment of your Web Asset

    Request a free non-intrusive security assessment of your website. Get a report with an overview of client-side security risks.

    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form

    Recommend a Topic

    • This field is for validation purposes and should be left unchanged.

    Partner with Us on the next episode

    • This field is for validation purposes and should be left unchanged.

    Watch On-demand Webinar

    • This field is for validation purposes and should be left unchanged.
    Start PreCrime Network for Free

    Oops! We could not locate your form.

    Book a Free Demo Today

    Get Your Free Trial

    Oops! We could not locate your form.

    Get Your Free Trial
    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form
    • This field is hidden when viewing the form
    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form