Question

Difficulty: EasyLogin Security, Login IP Ranges, and Login Hours

A Salesforce Administrator needs to ensure that call center representatives assigned to a specific profile are completely denied access to Salesforce if they attempt to log in from an IP address outside their corporate network range. Which security setting should the administrator configure to enforce this strict login restriction?

  1. Login IP Ranges on the specific user profileAnswer
  2. B
    Trusted IP Ranges under Network Access in Organization Setup
  3. C
    Network Access settings on individual user records
  4. D
    Session Security Levels in Org-Wide Session Settings

Answer

The administrator should configure Login IP Ranges on the specific user profile.
Configuring Login IP Ranges on the user profile strictly limits access to the designated IP addresses. Any user on that profile trying to log in from an unapproved IP address is completely blocked.

Step-by-Step Solution

1
Identify the security requirement
The requirement calls for complete denial of login access when originating outside specified IP ranges.
Hard login restriction outside defined IP boundaries is governed per profile in Salesforce.
2
Differentiate Profile IP Ranges from Org Network Access
Profile-level Login IP Ranges result in hard login prohibition outside the range. Organization-wide Network Access trusted IP ranges merely determine whether activation/identity verification is required.
Understanding the difference between access denial and identity verification is key to Salesforce login security configuration.

Key Concept

Profile Login IP Ranges vs. Org Network Access Trusted IP Ranges
Estimated Time:45s
Rate this question