Soru

Zorluk: Çok zorLogin Security, Login IP Ranges, and Login Hours

An administrator at Universal Containers needs to configure login access rules for two distinct user groups:
1. Customer Support Representatives must be completely prevented from logging into Salesforce if their access attempt originates from outside the corporate office network.
2. Field Sales Representatives frequently work remotely and must be allowed to log in from any location, but should not receive identity verification challenges when working within the corporate office network.

Which configuration strategy should the administrator implement to meet both security requirements?

  1. Add the corporate office IP range to the Support Representative Profile Login IP Ranges, and add the corporate office IP range to Organization Network Access settings.Cevap
  2. B
    Add the corporate office IP range to Organization Network Access settings only, and ensure both user groups are assigned to profiles without IP restrictions.
  3. C
    Add the corporate office IP range to the Support Representative Profile Login IP Ranges only, which automatically grants identity verification exemptions across all profiles.
  4. D
    Set the corporate office IP range on the Support Representative profile and define a Profile Login IP Range of 0.0.0.0 to 255.255.255.255 on the Field Sales Representative profile.

Cevap

Add the corporate office IP range to the Support Representative Profile Login IP Ranges, and add the corporate office IP range to Organization Network Access settings.
Profile-level IP ranges enforce strict login restrictions, denying access to users assigned to that profile if they attempt to log in outside the specified IP range. In contrast, Organization-Wide Network Access (Trusted IP Ranges) allows users logging in from trusted IPs to bypass identity verification challenges without preventing them from logging in from untrusted external IPs (provided they verify identity). Therefore, adding the corporate range to the Support profile blocks off-site Support logins, while adding the range to Organization Network Access ensures remote Sales Reps can log in seamlessly when visiting the corporate office without restricting their remote access.

Adım Adım Çözüm

1
Analyze the requirement for Customer Support Representatives.
Strict restriction requiring complete access denial outside the corporate network.
Profile-level Login IP Ranges restrict login access completely if an IP is outside the specified range.
2
Analyze the requirement for Field Sales Representatives.
Allow access from anywhere, but bypass activation/MFA challenges when on the corporate network.
Organization-wide Network Access (Trusted IP Ranges) allows users to bypass identity verification from specified IPs while still allowing access from untrusted IPs via verification.
3
Combine both configurations.
Apply Profile IP Ranges to the Support profile and set Organization Network Access for the corporate IP range.
This satisfies both the hard block for Support Representatives and the activation challenge exemption for Sales Representatives.

Anahtar Kavram

Difference between Profile Login IP Ranges (hard restriction) and Organization Network Access (identity verification bypass)
Bu soruyu puanla