A system administrator is provisioning access for a new cohort of remote customer service representatives. Security policy requires that these users be strictly blocked from logging into Salesforce whenever they are outside the corporate VPN IP address range. If a representative attempts to log in from an unapproved IP address, access must be completely denied rather than prompting for identity verification. Which setting should the administrator configure to enforce this requirement?
- Add the corporate VPN IP address range to the Login IP Ranges section of the custom profile assigned to the representatives.Cevap
- BAdd the corporate VPN IP address range to Network Access under the Organization-Wide Security Controls.
- CCreate a permission set with the corporate VPN IP ranges defined and assign it to each representative.
- DConfigure an automated flow to freeze user accounts whenever a login occurs from an unverified IP address.
Cevap
Add the corporate VPN IP address range to the Login IP Ranges section of the custom profile assigned to the representatives.
Specifying IP ranges within the Login IP Ranges section of a user's Profile enforces strict location-based access control. Any authentication attempt originating outside these defined profile IP boundaries is restricted and denied immediately.
Adım Adım Çözüm
Anahtar Kavram
Profile Login IP Ranges enforcement vs. Organization-Wide Network Access trusted IPs