Soru

Zorluk: OrtaUser Management and Provisioning

A Salesforce Administrator at a regional healthcare network is provisioning system access for remote telemetry nurses. Company compliance rules mandate that users with the Telemetry Nurse profile must be completely blocked from logging in whenever their connection originates from outside the hospital's secure VPN IP address range. Which configuration should the administrator implement to meet this security requirement?

  1. Define the designated IP address range under Login IP Ranges on the Telemetry Nurse Profile.Cevap
  2. B
    Add the designated IP address range to Network Access under Security Controls in Setup.
  3. C
    Create a custom Permission Set containing the allowed IP range and assign it to the telemetry nurses.
  4. D
    Freeze the user accounts automatically whenever an off-network IP address is detected during authentication.

Cevap

Define the designated IP address range under Login IP Ranges on the Telemetry Nurse Profile.
Defining the allowed IP range under Login IP Ranges on the user's Profile explicitly restricts authentication so that any login attempt originating outside the designated IP range is denied completely.

Adım Adım Çözüm

1
Analyze the compliance requirement.
The requirement specifies that users must be completely denied access (blocked from logging in) if attempting to connect outside a specific IP range.
Salesforce provides two main places for IP management: Profile Login IP Ranges (restrictive enforcement) and Org-wide Network Access (trusted IP list to bypass identity verification).
2
Evaluate Profile Login IP Ranges capability.
Setting IP ranges on a specific Profile strictly limits user logins to only those specified IP addresses. Any login attempt outside this range is hard-blocked.
Profile-level Login IP Ranges satisfy the mandate to block off-network access for users assigned to that profile.

Anahtar Kavram

Profile Login IP Ranges vs. Org Network Access
Bu soruyu puanla