Step-Up Authentication Uses Salesforce MFA Instead of Okta for Report Actions
Last Updated:
Overview
Salesforce does not support using external identity providers like Okta for step-up authentication. Administrators attempting to configure step-up authentication for Salesforce must use Salesforce native multi-factor authentication mechanisms instead. It is important to note that is for Report Actions carried out in the Salesforce application, and does not apply to MFA requirement for accessing Salesforce.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Salesforce
- Step-Up Authentication
Solution
Why does Salesforce prevent Okta from performing step-up authentication?
Salesforce enforces a strict security policy requiring native multi-factor authentication in step-up scenarios. When a user accesses a highly privileged resource or performs a restricted action in Salesforce, Salesforce requires a higher level of assurance. Salesforce does not delegate this specific high-assurance verification to external identity providers like Okta.
How is step-up authentication configured for Salesforce?
Administrators must configure step-up authentication directly within the Salesforce platform using Salesforce's native multi-factor authentication tools. Review the Salesforce documentation for specific configuration requirements and limitations regarding external identity providers.
