Soru

Zorluk: OrtaLogin Security, Login IP Ranges, and Login Hours

A Salesforce administrator at OmniTech Solutions needs to enforce strict access controls for compliance officers assigned to the Custom Compliance Auditor profile. The compliance officers must be allowed to access Salesforce only between 8:00 AM and 6:00 PM, Monday through Friday. Additionally, if these users attempt to log in from an IP address outside the corporate network, access must be completely denied rather than prompting for multi-factor identity verification. Which two configuration steps should the administrator execute on the Custom Compliance Auditor profile to meet these requirements?

  1. Define Login Hours on the profile to permit access between 8:00 AM and 6:00 PM, Monday through Friday.Cevap
  2. Add the corporate network IP addresses to the Login IP Ranges section of the profile.Cevap
  3. C
    Add the corporate network IP addresses to the organization-wide Network Access trusted IP list.
  4. D
    Configure Business Hours in Organization Company Information to limit user session activity to weekdays.

Cevap

The administrator must define Login Hours on the profile to permit access between 8:00 AM and 6:00 PM Monday through Friday, and add the corporate network IP addresses to the Login IP Ranges section of the profile.
To satisfy both requirements, security settings must be enforced at the profile level. Defining Login Hours restricts authentication to Monday through Friday from 8:00 AM to 6:00 PM. Specifying Login IP Ranges on the profile ensures that any login attempt outside the defined corporate IP range is completely rejected, rather than prompting the user for identity verification.

Adım Adım Çözüm

1
Evaluate time restriction requirements
Login Hours on the user profile control the exact days and time windows during which users can authenticate.
Profile-level Login Hours enforce a strict time window and deny authentication outside the defined schedule.
2
Evaluate IP address restriction requirements
Login IP Ranges defined on a profile hard-block any login attempt coming from outside the defined IP range.
Profile IP ranges act as a hard restriction (denying login), whereas organization-wide Network Access trusted IPs merely bypass identity verification prompts.

Anahtar Kavram

Profile-Level Security: Login Hours and Login IP Ranges
Bu soruyu puanla