Identity Verification and Device Activation Settings
5 minutes
5 Questions
Identity Verification and Device Activation Settings in Salesforce help protect user accounts by confirming the identity of users when they log in from unrecognized devices, locations, or IP addresses. These features add an extra layer of security beyond just usernames and passwords, reducing the r…Identity Verification and Device Activation Settings in Salesforce help protect user accounts by confirming the identity of users when they log in from unrecognized devices, locations, or IP addresses. These features add an extra layer of security beyond just usernames and passwords, reducing the risk of unauthorized access.
Device Activation prompts users to verify their identity when Salesforce detects a login attempt from a new or unfamiliar device or browser. When triggered, the user must confirm their identity through a verification method, and the device can then be added to a list of activated or trusted devices, so future logins from that device do not require repeated verification.
Identity Verification methods include several options that administrators can configure. Users may receive a one-time verification code sent to their registered email address, a code sent via text message (SMS) to their mobile phone, a code generated by the Salesforce Authenticator mobile app, or codes from third-party authenticator apps such as those using time-based one-time passwords (TOTP). Salesforce Authenticator also supports push notifications, allowing users to approve or deny login attempts with a single tap.
Within Setup, administrators can manage these settings under Identity Verification. Here they control which verification methods are enabled, set expiration times for verification codes, and decide whether users can use email as a fallback method. Administrators can also enforce stronger security by requiring multi-factor authentication (MFA) for all users.
Additionally, admins can review and manage users' verified devices and disconnect any that appear suspicious. The Identity Verification History provides an audit trail showing when and how users verified their identity, helping monitor security events.
By properly configuring these settings, administrators strengthen organizational security, ensure compliance requirements are met, and help safeguard sensitive data from potential threats while maintaining a smooth login experience for legitimate users.
Identity Verification and Device Activation Settings
Identity Verification and Device Activation Settings are essential security features in Salesforce that help protect user accounts from unauthorized access. As a Salesforce Administrator, understanding these settings is crucial for maintaining a secure environment while ensuring users can access their accounts smoothly.
Why It Is Important Identity verification adds an extra layer of protection beyond just a username and password. When a user logs in from an unrecognized device, location, or IP address, Salesforce can prompt them to confirm their identity. This helps prevent malicious actors from gaining access even if they have compromised credentials. For administrators, configuring these settings correctly balances strong security with a positive user experience.
What It Is Identity Verification refers to the process where Salesforce challenges a user to prove they are who they claim to be. This can happen through several methods, such as a verification code sent via email, SMS text message, an authenticator app, or a security key.
Device Activation is the process where a user confirms a new or unrecognized device is trusted. Once activated, the device is remembered, reducing the frequency of verification prompts for that user on that specific device.
How It Works When a user attempts to log in, Salesforce evaluates the login context, including the IP address, browser, and device. If the login appears unusual, the system triggers an identity verification challenge. The available verification methods include:
• Verification code via email sent to the user's registered email address • Verification code via SMS sent to a registered mobile number • Salesforce Authenticator app for push notifications and one-tap approval • Time-based one-time passwords (TOTP) from third-party authenticator apps • Security keys such as U2F or WebAuthn devices
Administrators can control these behaviors through the Identity Verification page in Setup. Here you can decide which verification methods are permitted, set how long a device stays activated, and configure whether email or SMS verification is allowed.
Additionally, administrators can manage trusted IP ranges. Logins that originate from within these ranges may skip identity verification, streamlining access for users on the corporate network.
Key Configuration Options • Verification Methods: Enable or disable specific methods like SMS, email, or authenticator apps. • Device Activation: Choose whether users can activate devices to be remembered as trusted. • Login IP Ranges: Define trusted network ranges at the profile level to reduce verification prompts. • High Assurance Sessions: Require stronger verification for sensitive operations or data access.
How to Answer Questions in an Exam When facing exam questions on this topic, focus on matching the security requirement to the correct feature. Questions often present a scenario where a company wants to enhance login security or reduce unauthorized access. Identify whether the answer involves identity verification methods, device activation, trusted IP ranges, or multi-factor authentication.
Pay close attention to keywords like unrecognized device, verification code, trusted network, and high assurance session, as these point toward specific configuration choices.
Exam Tips: Answering Questions on Identity Verification and Device Activation Settings • Remember that identity verification is triggered when a login occurs from an unrecognized device or location. • Know the difference between the various verification methods and when each is appropriate for a scenario. • Understand that trusted IP ranges set at the profile level can reduce how often users are challenged. • Recognize that device activation allows a device to be remembered as trusted, cutting down on repeated prompts. • Be aware that Salesforce Authenticator supports both push notifications and one-tap approvals for a smoother experience. • When a question mentions sensitive data access, consider high assurance sessions as the likely answer. • Do not confuse identity verification with password policies, as these are separate security controls. • Read scenarios carefully to determine whether the goal is stronger security or a better user experience, then choose the setting that best balances both.