Like many enterprises, our SalesForce Org was setup with a requirement to change your password every 90 days. Unfortunately, the requirement to change the password usually comes at an inconvenient time, without warning and when I am in a hurry. When users change passwords under stress it is likely they will not remember it or make a mistake that locks them out of their account until an admin can reset it for them.
As a result, we have a lot of users who then are locked out of their SalesForce account after three attempts with the wrong password.
I have a quick solution for this that lets me change my Salesforce password at my leisure and not at SalesForce's insistence. I setup a Google Calendar event with a two day prior email notification that repeats every 3 months.
Now I receive an email alert 2 days prior to needing to change it. I then have 48 hours to open up LastPass, generate a new random, long password and paste it into SalesForce's password reset.
SalesForce requires the knowledge of the current password in order to change a password. LastPass remembers your password history so if for some reason you don't know your previous password you can always find it in your LastPass Password history.
SalesForce will also reset your security token when you reset your password. I copy and paste this into the notes section of LastPass for the SalesForce record.
I am a big fan of LastPass and enccourage everyone to look into using LastPass to securely manage passwords. When you combine LastPass with the Yubikey two factor authentication technology you have an terrific solution to secure access to passwords.


No comments:
Post a Comment