A Salesforce Administrator at a cloud security enterprise needs to provision access for a newly hired internal audit team. The audit team members require standard platform permissions. However, corporate compliance mandates that these specific users must be strictly prohibited from logging into Salesforce when working outside the corporate network range (). Attempting to log in from an unauthorized IP address must result in immediate access denial rather than triggering an identity verification challenge. Which configuration should the administrator implement to meet these requirements?
- AAdd the corporate IP range to the Network Access settings under Organization-Wide Security Settings.
- Configure the allowed login IP ranges directly on the profile assigned to the internal audit team members.Answer
- CCreate a Permission Set defining the allowed IP range restrictions and assign it to each audit team member.
- DFreeze the internal audit user accounts whenever they leave the corporate network to prevent off-site authentication.
Answer
Configure the allowed login IP ranges directly on the profile assigned to the internal audit team members.
Configuring Login IP Ranges at the Profile level strictly enforces location-based login controls. If a user assigned to that profile attempts to authenticate from an IP address outside the configured range, Salesforce denies access immediately without issuing an identity verification challenge.
Step-by-Step Solution
Key Concept
Profile Login IP Ranges vs. Network Access IP Ranges
Estimated Time:2m 0s