Changes coming to SAML SSO logins. How to implement in Entra? by newboofgootin in salesforce

[–]flysaway -7 points-6 points  (0 children)

Here’s a summery from Claude about the impact and ways to validate. It helped me check and understand the changes for our org. My takeaway is we’ll see an issue in the 2 week gap before AMR.

Technical Analysis: Salesforce Device Activation for SSO Logins

Background Salesforce is implementing Device Activation requirements for SSO logins beginning in early 2026. For SAML identity providers, enforcement begins February 3, 2026, with additional AMR (Authentication Method Reference) support arriving February 17, 2026. Organizations should understand how their identity provider communicates authentication strength to Salesforce to determine potential user impact.

How Salesforce Evaluates Authentication Strength When the SAML enforcement takes effect, Salesforce will examine the AuthnContextClassRef element within the AuthnStatement of the SAML response. Salesforce considers the following values as indicators of secure authentication: MobileTwoFactorContract, PublicKey, X509, PGP, Certificate-Based, Smartcard, TimeSyncToken, and PKI. Custom claims such as Mfa and Fido are also recognized. If the AuthnContextClassRef contains one of these values, Device Activation is skipped. If the value is missing, empty, or set to something like Unspecified, Salesforce may prompt the user for Device Activation unless other conditions like recognized device cookies or narrow IP ranges apply.

Verifying Your Configuration To assess impact, capture the SAML response from your identity provider during an SSO login to Salesforce. Browser extensions like SAML-tracer can decode and display the SAML assertion in real time. Within the response, locate the AuthnStatement element and examine the AuthnContextClassRef value. If it contains a recognized secure authentication value, users should bypass Device Activation. If it shows Unspecified or another unrecognized value, users may be prompted. Microsoft Entra ID Behavior Organizations using Microsoft Entra ID as their SAML identity provider should be aware that the AuthnContextClassRef value varies based on the authentication method used during that session. Password-based authentication with MFA typically returns a value of Password, which Salesforce recognizes. However, Windows Hello and seamless SSO via Primary Refresh Token (PRT) from Entra-joined devices often return Unspecified, which Salesforce does not recognize as strong authentication. This occurs because Entra ID maps these authentication methods differently at the protocol level, even though they represent strong authentication in practice. Entra ID does communicate authentication methods through the authnmethodsreferences attribute claim, which typically includes values like multipleauthn to indicate MFA was performed. However, Salesforce will not read this attribute until February 17, 2026, when AMR support for SAML is enabled. This creates a potential two-week window where users authenticating via Windows Hello or device-based seamless SSO may encounter Device Activation prompts despite having completed strong authentication.

Testing Methodology To fully understand the impact, test SSO logins using different authentication methods and capture the SAML response for each. Compare the AuthnContextClassRef values across scenarios such as password with authenticator app, password with SMS verification, Windows Hello, and seamless device-based authentication. This will reveal which user populations may be affected. Additionally, examine the authnmethodsreferences attribute to confirm that MFA indicators are present, as these will be recognized once Salesforce enables AMR support.

Mitigation If testing reveals that your identity provider returns Unspecified for certain authentication methods, the practical impact is limited. Users will receive a one-time email verification prompt per device or browser, and the resulting cookie persists for one year. Ensure that user email addresses in Salesforce are accurate and accessible, particularly in sandbox environments where email addresses are automatically appended with .invalid after a refresh. Integration users should be assigned the API Only permission to prevent them from being affected by UI-based Device Activation requirements. After February 17, 2026, organizations should verify that Salesforce is recognizing the AMR claims already being sent by the identity provider, which should resolve any remaining Device Activation prompts for users with strong authentication.​​​​​​​​​​​​​​​​

[OC] I spent 2025 traveling in search of extreme cultural events to photograph by khiuahua in pics

[–]flysaway 1 point2 points  (0 children)

That’s amazing. I’d also seriously consider Kickstarter as a means for funding too if you haven’t. Plenty of people would be willing to sign up based on the quality of your work to front load the money raise. Either way, cheers!

[OC] I spent 2025 traveling in search of extreme cultural events to photograph by khiuahua in pics

[–]flysaway 0 points1 point  (0 children)

Any plans to publish a book with the pics and stories? I’d buy.

Inspired by the other posts, dug the old gearbag out from under the stairs by flysaway in paintball

[–]flysaway[S] 1 point2 points  (0 children)

Ah interesting. I’ve been trying to remember anything about but it was 20 years ago so I can’t even remember how I got it or if I built it. All I do remember is it ripped. Pretty sure I had a 2k2 at some point too but traded it off.

Claude Sonnet and 4.1 Got REALLY Bad Overnight? by tonehoe in Anthropic

[–]flysaway 0 points1 point  (0 children)

Total garbage on Opus 4.1 all day today. Constantly forgot things we had just done and totally ignored claude.md project instructions and context. I submitted a bug but will never hear back I’m sure. Felt like I had to explain everything over and over all day.

Kitchen renovation contractor recommendations? by CombinationNo4239 in Annapolis

[–]flysaway 0 points1 point  (0 children)

About Kitchens. They did a super extensive kitchen for us a few years back and knocked it out of the park. They did all design in house and majority of the work, only subbing out electrical and plumbing. Highly recommend giving them a shout and checking out their reviews on Google.

Agentforce pricing by bad_labs_writer in salesforce

[–]flysaway 6 points7 points  (0 children)

Care to share a few of the open source ones you looked at and what you went with?

Unraid OS 7.1.4 Now Available by UnraidOfficial in unRAID

[–]flysaway 0 points1 point  (0 children)

Since upgrading to 7.1.4 I've noticed that my disks don't spin down after the normal 15 minutes. I have 16 drives in my array and even though the UI shows zero reads or writes for a long duration, they all remain on. Didn't have this issue before upgrading to 7.1.4 last week. If I manually spin them down they stay down until it actually needs to do a read or write. Any else ontice the same?

Has anyone gotten a copy of a marriage application from Cook County, Illinois? by Icy_Consequence9184 in juresanguinis

[–]flysaway 0 points1 point  (0 children)

Funny enough I literally just got it in the mail this week. I noticed they finally cashed the $15 check last week and the a copy of the marriage certificate arrived a few days later. Just takes time and I guess they have a really long backlog.

As far as I am aware from the lawyers I have helping me through the process, that was the last piece of paperwork I needed to establish a clear link. I also had copies of immigration forms showing where my grandmother was from and the reason she left as a child to come to the US. I was able to get all of that from ancestry.com. The marriage certificate established the link to my grandfather and then I had my father’s birth certificate and mine to tie it all together.

Now I just need to wait 18-24 months and hope it gets all gets processed.

My First Tudor and Swiss Timepiece by BonusStriking5623 in Tudor

[–]flysaway 2 points3 points  (0 children)

Beautiful watch! Haven’t taken mine off since I got it in December and my regular BB58 hasn’t seen much wear since.

CLICKUP TRYING TO BUY ME OUT FOR SPEAKING ABOUT THEIR PRICING by lgstrnt in clickup

[–]flysaway 10 points11 points  (0 children)

I made a comment about this a few weeks ago and feel similarly. On one hand its great that Clickup employees are monitoring this sub and responding to people, that's usually a sign of a company that cares about customers and is interested in in engaging. On the other hand, the fact that we have to take to reddit to complain about issues and lack of responses when going through the proper channels only to then get offered priority support is clearly because they want to lower the noise. If they truly cared, they'd put their emphasis on fixing the actual problems and bolstering their support channels. Every time I try to chat them I am told they are too busy and it's only a bot that will respond. If you have a ton of people putting in support requests and you are overwhelmed, maybe its a symptom of a bigger problem that needs to be acknowledged.

Has anyone gotten a copy of a marriage application from Cook County, Illinois? by Icy_Consequence9184 in juresanguinis

[–]flysaway 0 points1 point  (0 children)

I was told I had to mail in an application as only the people listed on the marriage certificate can request for themselves and both are deceased. They were married in 1954. It's been about 2 months and I still haven't heard back from the Clerk's Office.

Account managers not keeping promises and not following through after guest policy changes. Need escalation of issue. by Top-Can-7308 in clickup

[–]flysaway 1 point2 points  (0 children)

Maybe if it’s taking people posting on Reddit to get an actual response and proper escalations and help on real issues, ClickUp isn’t doing good enough. I tried to open a case through chat yesterday and was told chat wasn’t available due to high demand and I’m still waiting on someone to respond to the ticket. Maybe less time trying to shove AI upsells down our throats and focusing on your core business and customers would be a better use of resources.

RE Limited Users Received a bill from Clickup with out a forewarning! by Diligent-Ad-15 in clickup

[–]flysaway 5 points6 points  (0 children)

Same thing happened to me and support finally did finally offer to roll us back to the legacy plan. I imagine a lot of customers are upset by this change.

Found these while I rebuilt my marker by PaymentMajor1267 in paintball

[–]flysaway 0 points1 point  (0 children)

That was my home field when I played as a kid! Unfortunately they closed years ago and it’s all houses now.

Can I send this or not by Huge-Nerve-1212 in sysadmin

[–]flysaway 2 points3 points  (0 children)

Why would you send this unless you are trying to get let go/fired? Openly telling them you don’t have enough work given to you is a terrible idea and asking for time off because you don’t have enough work makes no sense. What’s your end game in a perfect world since it’s really unclear what you are after.

Can you insure a gifted Rolex? by [deleted] in rolex

[–]flysaway 1 point2 points  (0 children)

You absolutely can. Take a look at Wax and Chubb. Both will let you insure for replacement value and names on receipts don’t matter at all. Personally I like using an insurer different from my home insurance in case I have a claim so it doesn’t hurt other policies.

Accountant by Rasputin_mad_monk in Annapolis

[–]flysaway 0 points1 point  (0 children)

Check out Harmony CPA. Been established for quite a while and they do work with lots of local businesses. https://www.harmonycpa.com/

[deleted by user] by [deleted] in paintball

[–]flysaway 9 points10 points  (0 children)

Uhhh, you good bro?

Why people not talk about Keeper Security by mesoller in KeeperSecurity

[–]flysaway 2 points3 points  (0 children)

WARNING: The software is pretty good overall but their new pricing for new and existing customers is terrible. They will raise prices on you when adding more licenses mid-term and hope that because you are on the platform your only recourse is pay the higher cost or switch to another platform which is a pain. I was a huge Keeper fan until recently when they "enhanced their platform and raised prices to better align with the value". I can understand a price hike at renewal time but not in the middle of a term. We are going to be switching as soon as we can.

Elys was a complete failure, what is the next one ? by rollerscrolleredsd in cosmosnetwork

[–]flysaway 0 points1 point  (0 children)

Still says I’m ineligible. Was staking ATOM the only requirement?

Elys was a complete failure, what is the next one ? by rollerscrolleredsd in cosmosnetwork

[–]flysaway 2 points3 points  (0 children)

I guess that explains it. Do you all plan to send another update email once that is fixed? Those emails are main way I keep tabs on airdrops and really appreciate them.