Question

Difficulty: EasyUser Management and Provisioning

A Salesforce Administrator needs to restrict access so that sales agents can log into Salesforce only when they are physically present at the corporate office. If an agent attempts to log in from an IP address outside the corporate network, the login attempt must be denied. Where should the administrator configure these IP restrictions to meet this requirement?

  1. A
    Network Access settings under Organization-Wide Setup
  2. Login IP Ranges on the sales agents' assigned ProfileAnswer
  3. C
    Login IP Ranges configured within a Permission Set assigned to the agents
  4. D
    User Freeze settings configured on each individual User record

Answer

Login IP Ranges on the sales agents' assigned Profile
Configuring Login IP Ranges on the user Profile strictly restricts login access. Any login request originating outside the specified ranges on the profile is automatically blocked.

Step-by-Step Solution

1
Identify the security requirement.
Logins from outside the designated corporate network must be explicitly denied.
Determines whether to use organization-wide trusted IPs or profile-based login restrictions.
2
Evaluate the behavior of Profile Login IP Ranges vs. Org Network Access.
Profile Login IP Ranges enforce login restrictions by blocking unlisted IPs, whereas Network Access only controls identity verification prompts.
Selects the feature that matches the strict denial requirement.

Key Concept

Profile Login IP Ranges vs. Network Access (Trusted IPs)
Estimated Time:45s
Rate this question