Troubleshooting: Salesforce1 App Does Not Recognize Device Fingerprint

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    The Salesforce1 mobile app does not honor a device's stored fingerprint, so users are prompted for two-factor authentication every time even though a fingerprint has already been logged for their device.

     

    Cause

    The Salesforce1 app does not accept cookies, so when SecureAuth tries to match the device's fingerprint ID with a cookie ID, the match always fails.

     

    Resolution:

    To resolve this:

    Change the device fingerprinting settings so SecureAuth no longer tries to match the fingerprint ID to a cookie ID. At minimum, change the following two settings:

    • Under System Components, lower Host Address/IP from 15% to 5% or less.
    • Under Mobile Settings, change Match FP Id in Cookie from True to False.

    The Weights of FP Components section under System Components, with Host Address/IP, Timezone, and Screen Resolution highlighted.

    The Mobile Settings section, with Match FP Id in Cookie set to False and the Authentication and Update thresholds highlighted.

    The following settings are optional, but make authentication more flexible:

    • Under System Components: Timezone to 6%, Screen Resolution to 10%.
    • Under Mobile Settings: Authentication Threshold to 90%, Update Threshold to 85%.


     

    Special Considerations

    Lowering these thresholds makes the second-factor bypass more lenient, which reduces security. Find the right balance between security and convenience for your environment before changing these settings.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.