Elektrine lite

← Feed

@SecureOwl@infosec.exchange

2026-09-16 20:43 UTC

Salesforce have somehow managed to implement a security control that lowers overall security, and pisses everyone off in the process - a rare achievement. Our setup is quite simple: my users SSO into our IDP, they have to use a strong authenticator (FIDO2, Biometric, App OTP etc.) - Then they login to Salesforce via SAML IDP sends a message in the SAML assertion to Salesforce that confirms they have used strong, phishing resistant auth. What used to happen was: Salesforce would be more than happy with the assertion that strong MFA had been used - and would let the people do what they needed to do. Now, however, they've decided that people who login via IDP's can no longer be trusted, so, when you do certain things like access a report from Salesforce, you must do MFA again with a "Salesforce-Native authenticator". According to them: "Step-up authentication must be completed using a Salesforce-native verifier, it cannot be delegated to an external SSO identity provider (IdP). Even if a user authenticates into Salesforce via SSO, they are still required to satisfy the step-up challenge using one of the following: A Salesforce-registered MFA method (such as Salesforce Authenticator, a TOTP authenticator app, a security key, or a built-in authenticator like Face ID or Touch ID) A one-time passcode (OTP) delivered via email or SMS to the contact information associated with their account This means SSO users who do not have a Salesforce-native verifier registered will fall back to email or SMS OTP to complete the step-up challenge." Read that last part. None of my users have Salesforce-native verifiers, because they are all associated with our IDP, where they have strong auth - so, the secure code they get is A) SMS or B) over Email - because its more secure and trustworthy than FIDO2, apparently. Truly incredible. https://help.salesforce.com/s/articleView?id=005321566&type=1 #infosec

Replies (1)

  • @leerayl@infosec.exchange 2026-09-16 21:31

    @SecureOwl@infosec.exchange wow Salesforce actually implemented reading enveloping assertions. Pretty sure this is going to be seen more and more as providers fight for auth source of truth.

    Open ##4730858