Salesforce contains some of the most important business data, like customer details, sales data, financial information, and internal communication. Because of this, keeping this data safeguarded is a priority and needs to go beyond having strong passwords. Salesforce admins can configure Session Settings so that users are able to log in as per a particular condition and thereby minimize session hijacking, unauthorized access, and exposed sessions.
Plus the understanding of Salesforce Security topics like Salesforce passwords, covered in Salesforce Admin Certification are also important because these settings are closely connected to Salesforce access and security management.
We will cover the most important Salesforce session security settings and provide detailed steps to set them up in this article.
What Are Salesforce Session Security Settings?
A Salesforce session is generally created after a user logs in successfully. The session helps the user to navigate the platform without authenticating at every single page. Still, an active session can present a security threat if the user leaves the device unattended or the session can be hacked. To mitigate such risks, Salesforce has different measures that administrators can set up. You can access the main settings and review the available security options; you can go to,
Setup → Session Settings
The exact options available can vary depending on your Salesforce edition and configuration.
1. Configure Session Timeout
Controlling the allowed period of session inactivity without having an action is a very simple way to enhance session security.
A short timeout will make the computer unoccupied for a minimum period of time, thereby limiting access to Salesforce. Suppose an employee is on a shared computer and forgets to log out; then an appropriately configured session timeout can automatically end the inactive session.
When you decide on a timeout duration, you should evaluate your organization’s working context. A too brief timeout can be a security boost; on the other side, it might hassle users who have their work regularly going in Salesforce.
Salesforce, for connected apps, also offers managing session timeout through policies at the connected-app level. Per the connected app, profile and organization level hierarchy, Salesforce sets the Session Timeout settings
2. Lock Sessions to the Original IP Address
Session Hijacking is the act of an unauthorized party taking control of your web session, using it to impersonate you and gain access to the system. Salesforce has the option to lock sessions to the IP address from which they originated, which, when enabled, ensures a user’s session will only be valid through the IP address that launched the session in the first place.
This setting can help lower risks for the attacker who managed to steal the session identifiers using different network. However, enabling this option takes the administrators and employees to weigh the pros and cons of their network usage. Users who roam between networks regularly, make use of mobile connections or work behind different kinds of dynamic IP addresses might be kicked out of their session and forced to login again due to a mismatch in the IP addresses. This can be really frustrating to such users if they are required to login again and again for their legitimate work.
3. Lock Sessions to the Original Domain
The third way of securing Sessions would be to Lock Sessions to the Original Domain. If that option is turned on, administrators could have the option for the Lock sessions to the domain in which they were first used
It gives another means of safeguarding sessions by limiting access to the initial host domain on which the session was created. This method is recommended, and those session locking options are based on the IP address as a session security measure per Salesforce. This will be very handy for companies that have rigid rules about where Salesforce sessions are permitted to run at all. For example, the sales reps may work anywhere but not with the laptop at home; then it can be set via this feature.
4. Use Trusted IP Ranges Carefully
You can define areas of the network that users can access without being asked to confirm their identity if you use trusted IP ranges.
Click Setup -> Security -> Network Access to change these.
Users connecting to the instance from trusted IP addresses will not have to pass extra security challenges such as answering a phone call or entering SMS code whereas users connecting from outside those IP ranges could be asked to confirm their identity.
Note that Trusted IP ranges and profile-based login IP restrictions are not the same.
By using trusted IP ranges, the system can skip some of the identification steps that require the user to prove his or her identity to the system. But with profile-based login IP constraints, it may become impossible for a user to log in from outside the allowed ranges of IP addresses.
This distinction is one that you would want to get into your mind when preparing for Salesforce admin certification since both configurations are about the network, but they achieve different things.
5. Enforce Login IP Ranges on Every Request
Salesforce adds the Enforce login IP ranges on every request checkbox to Session Settings. If the feature is made available, the IP ranges of the login profiles will be validated at each request on any page. Because of this, even during login, only initial checking will take place.
This extra layer of checking helps prevent such sessions from becoming active when a user travels between or is switching networks. It is highly recommended that administrators thoroughly test this configuration change before rolling it out to a lot of users, mainly if these users often use a virtual private network (VPN), mobile devices, and the Internet in general, or have some of their applications integrated with other systems.
6. Consider High-Assurance Session Security
Each Salesforce operation does not demand the same degree of authentication from users. High-assurance session security can protect mostly sensitive activities.
Administrators can use Salesforce to require high-assurance sessions only for certain kinds of sensitive activities such as reports, authentication provider certificates, and connected apps. Under the right configuration, the user may be compelled to log into his/her account again to be identified as the original through step-up authentication.
One might consider this method a way of imposing stronger authentication without affecting the whole system when a business wants to protect highly sensitive actions.
High-assurance settings should be carefully tested by admins; Salesforce advises that setting a profile’s Session Security Level Required at Login as High Assurance may affect asynchronous Apex processing.
7. Terminate Sessions After Password Resets
A further helpful feature is to automatically end all of a user’s active sessions if a password gets reset by an administrator.
Such measures are mainly important in situations where the user’s password could have been revealed. Closing existing sessions ensures that no one would have continued to access Salesforce from a previously opened session. This control is one of Salesforce’s suggested session security best practices listed by the company.
Final Thoughts
Salesforce session security controls, such as session timeout, IP address restrictions, trusted sources, session lock, and authentication for high assurance, help admins reduce unauthorized access while securing sensitive business data at the same time.
Picking the best security options is a matter of finding the right balance between securing information and making sure the security is not frustrating to the users. Too restrictive security can actually prevent legitimate users from accessing the system; however, too lenient security measures can create unsecured entry points.
If you are aiming at doing a Salesforce admin certification, understanding these measures is going to be beneficial to you not only for your certification but also in a very responsible Salesforce environment management practice.
Salesforce Admins who are keen on acquiring hands-on experience through online Salesforce admin training can gain a practical understanding of implementing of the security settings, managing users and other fundamental administration tasks of Salesforce.




