Cloud Dynamics wants to tighten access controls for its workforce. The system administrator is tasked with configuring login restrictions based on location:
1. Users assigned to the 'Inside Sales' profile must be completely blocked from logging into Salesforce when outside the corporate network IP range ().
2. Users on all other profiles should be allowed to log in from anywhere, but should bypass multi-factor identity verification prompts only when logging in from the corporate network IP range.
Which configuration strategy achieves both requirements?
- Add the corporate IP range to Login IP Ranges on the Inside Sales profile, and add the same IP range to Organization-Wide Network Access.Cevap
- BAdd the corporate IP range exclusively to Organization-Wide Network Access and enable the strict IP restriction checkbox on the Inside Sales profile.
- CAdd the corporate IP range to Login IP Ranges on the Inside Sales profile, without configuring Organization-Wide Network Access.
- DAdd the corporate IP range to Organization-Wide Network Access for the Inside Sales profile, and configure Login IP Ranges under Session Settings for all other profiles.
Cevap
Add the corporate IP range to Login IP Ranges on the Inside Sales profile, and add the same IP range to Organization-Wide Network Access.
Defining IP ranges on the Profile enforces hard login denial outside the designated range, fulfilling the requirement for Inside Sales users. Meanwhile, adding the IP range to Organization-Wide Network Access establishes it as a trusted IP range for the entire org, allowing other users to bypass verification challenges at the office while retaining remote access capabilities.
Adım Adım Çözüm
Anahtar Kavram
Profile Login IP Ranges vs. Organization-Wide Network Access