Version Affected: All
Overview
The Salesforce1 mobile app does not honor a device's stored fingerprint, so users are prompted for two-factor authentication every time even though a fingerprint has already been logged for their device.
Cause
The Salesforce1 app does not accept cookies, so when SecureAuth tries to match the device's fingerprint ID with a cookie ID, the match always fails.
Resolution:
To resolve this:
Change the device fingerprinting settings so SecureAuth no longer tries to match the fingerprint ID to a cookie ID. At minimum, change the following two settings:
- Under System Components, lower Host Address/IP from 15% to 5% or less.
- Under Mobile Settings, change Match FP Id in Cookie from True to False.
The following settings are optional, but make authentication more flexible:
- Under System Components: Timezone to 6%, Screen Resolution to 10%.
- Under Mobile Settings: Authentication Threshold to 90%, Update Threshold to 85%.
Special Considerations
Lowering these thresholds makes the second-factor bypass more lenient, which reduces security. Find the right balance between security and convenience for your environment before changing these settings.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.