Skip to content
PodcastsBusinessSalesforce Admins Podcast

Salesforce Admins Podcast

Mike Gerholdt
Salesforce Admins Podcast
Latest episode

182 episodes

  • Salesforce Admins Podcast

    From Inbox Requests to a User Management System

    06/08/2026 | 38 mins.
    Today on the Salesforce Admins Podcast, we talk to Michelle Wolfe, Platform Engineer.
    Join us as we chat about how she built a Flow-powered user management system to handle requests, approvals, user creation, permissions, communications, and even onboarding.
    You should subscribe for the full episode, but here are a few takeaways from our conversation with Michelle Wolfe.
    Streamlining change requests with screen flows
    It's a good thing when your organization is growing, right? For Salesforce Admins, however, new hires need new accounts, and that means approvals, permissions, and onboarding. My guest this week, Michelle Wolfe, found herself in exactly this situation. She turned to Flow to build an automated user management system with no code, and she's here to tell us all about it.
    Michelle's company was bringing in 80+ people per new hire class, but the account creation request process was a mess. Managers would email a random member of the three-person admin team, and then they would manually create the account. So the first step was to wrangle the business process with a screen flow to get the correct information into Salesforce and create a case.
    But Michelle was just getting started. Now that everything was in Salesforce, she knew that she could use Flow to automate the rest of the process.
    New account creation with autolaunched flows
    Once the new user's information was approved by their manager, Michelle set up an autolaunched flow to spin up the account. This took care of data validation, configuring the correct permissions, and creating a username.
    Finally, a second autolaunched flow would close out the case and send two email actions: one to confirm the request, and one to welcome the new user. With help from Flow and Einstein Copilot, Michelle transformed a complicated manual business process into something streamlined, simple, and scalable.
    Partner with your training team for a fresh perspective on your org
    Michelle credits her success with how closely she works with her training team on enhancements. "Because they interact with new employees, they see things differently than someone who's been here for years and knows how we use our Salesforce," she explains. That fresh perspective helps her identify improvements she might otherwise miss.
    Listen to my full conversation with Michelle for more on how she used Flow to automate user management—we really get into the weeds. And make sure you're subscribed to the Salesforce Admins Podcast so you never miss an episode.
    Podcast swag
    Salesforce Admins on the Trailhead Store

    Admin Trailblazers Group
    Admin Trailblazers Community Group

    Social
    Michelle on LinkedIn

    Salesforce Admins on LinkedIn

    Salesforce Admins on X

    Mike on Bluesky social

    Mike on Threads

    Mike on X

    Full show transcript
    Mike:
    This week on the Salesforce Admins Podcast, I'm joined by Michelle Wolf to talk about what happens when user onboarding stops being a string of emails and becomes a real platform process.
    So Michelle built a Flow-powered system that handles requests, approvals, user creation, permissions, communications, and even offboarding, while keeping the admin team in control.
    We're going to talk about the automation behind it, but also the process decisions that make it accurate, secure, and useful for her business.
    Now, because when admins design access and onboarding well, they're not just saving time. They're protecting trust and helping people get productive faster.
    So listen in, subscribe, share this episode with an admin who has one too many user requests sitting in their inbox.
    I'll tell you who doesn't have too many user in requests sitting in their inbox, and that's Michelle.
    So let's get Michelle on the podcast.
    So Michelle, welcome to the podcast.
    Michelle Wolf:
    Thank you for having me, Mike.
    Mike:
    I think this is exciting because I can't recall the number of times I've had people on about onboarding users. And I think it's because whatever cool tool we have come out, it's the second thing people do. They're like, "Oh, I could do this, and I need to figure out how to do X, Y, and Z when I onboard people."
    Because it was like that with Flow. There was stuff with Chatter when that came out, "How do I onboard people and add them to groups?"
    And Jennifer Lee was at your session at Midwest Dreaming, and she thought it was just phenomenal. So I had to have you on the podcast to talk about it.
    But before we get into that, tell me a little bit about yourself, how you got started with Salesforce and what you do.
    Michelle Wolf:
    Yeah. So my journey started as a lot of ours as an accidental admin.
    I was working for a small family-run business who had Salesforce, and they were paying a consultant to basically be their full-time admin.
    And one day my manager walked into my office and said, "I don't want to pay them anymore. I need you to learn this."
    And I was like, "Okay."
    Mike:
    "I suppose."
    Michelle Wolf:
    Yeah. Why not? So yeah, that's what started my journey. And I skilled up on Trailhead and I was on it two, three hours a day trying to figure out how to be an admin in Salesforce. And this was back at the initial transition from Classic to Lightning.
    Mike:
    Ooh, fun.
    Michelle Wolf:
    So half of my early batches are on Classic. There just wasn't a ton of Lightning stuff out there yet.
    So I would build a lot in Classic and then flip it over to Lightning to see what it looked like because they did like the Lightning interface, which was great.
    So that started my journey. And then when I decided to part ways with that company, I took a different position and paused my admin career.
    And then about five years ago or so, I had an opportunity to be a product SME for Salesforce. And I was like, "Yes, I miss this product. I miss doing this. I miss being able to make things better with just the click of the button. So let's go do this."
    And I jumped in both feet and never looked back. And so I've been an active admin for a little over five years now.
    And I'm a Flownatic. Anything I can automate, I am doing it.
    Mike:
    I love it. Active admin as opposed to passive.
    Michelle Wolf:
    Exactly.
    Mike:
    I don't know. So I love when you started because I remember those times and the reason there wasn't enough Lightning things is we were all writing it as fast as we could.
    Michelle Wolf:
    Yeah, I know it.
    Mike:
    It's kind of like learning to drive with a manual. And then they're like, "Oh, well, here's an automatic." And you're like, "Oh, I already know how to drive with a manual." I mean, if you knew how to do things in Classic, then doing stuff in Lightning was just that much easier, in my opinion anyway.
    Michelle Wolf:
    Yeah. I agree. I agree.
    And the user experience was better for my users. They liked the layout and the feel. It jived with their personalities better instead of that very formal grid-looking everything.
    Mike:
    I mean, that was the internet at a certain period in time. And then it grew up and it was like your eyes don't have to squint with white space.
    Michelle Wolf:
    Right.
    Mike:
    Every field just went from tight polyester pants to sweatpants. And it was like, "Yay."
    Michelle Wolf:
    Exactly.
    Mike:
    Let's talk about being a Flownatic because I've talked with Jen. I know Jen said she was in your session.
    I really think, I mean, outside of just it's so incredibly powerful, the amount of things that you can do on the Salesforce platform without writing a single line of code. Flow is one of those.
    And I remember it was 100 years ago that I saw Flow for the first time at Dreamforce when I was a customer. And I think they called it Business Process Management or something. And it was an app you had to download, and then you had to upload schemas to it.
    It's since graduated into a much more robust tool. But the nice thing is once you know that, I mean, caveat emptor because AI runs off of all the flows. I mean, if you're good at Flow, there's very few things you can't make Agentforce do.
    So tell me a little bit about why you built onboarding with Flow.
    Michelle Wolf:
    Yeah. The company I was with found themselves in a really big period of growth, which was really amazing.
    But the new hire classes were like 80 people. And I just could not bring myself to want to spend a week of my life just filling in these boxes to make new users.
    It was really so time-consuming. And one typo here, one missed field here. My validation rules didn't check out. It was just a pain. It's just very mind-numbing.
    And I was like, "There has to be a better way."
    And I went through the different variations of the Add Multiple Users. It's an out-of-the-box function, except I couldn't put my custom fields on there, which means I couldn't save my users because we had validation rules in place.
    And then I experimented with a bulk upload, but it was such a pain because if I would typo a field, I would mess up my entire formula.
    Mike:
    Yeah.
    Michelle Wolf:
    And I was like, "There has to be a better way. There just has to be a better way." And-
    Mike:
    Plus then all you're doing is just creating the user.
    Michelle Wolf:
    Exactly.
    Mike:
    With Flow, you can do so much more.
    Michelle Wolf:
    Exactly. So by converting it to a Flow, I had a screen. I used my screen flows, and I leveraged the fact that the onboarding team is already putting that information into an email or something. Well, just go here and put it in a case for me. Just hit this button, pull out the fields. Now I don't have to do this.
    And then I used that screen flow to make a case so I can track my productivity, when the requests are coming in, when the requests are due by, who's doing the request.
    We started with just managing cases manually and making the users off the cases. And we had built in the approval process to make sure that someone else was double checking the inputs. Did they spell their name right? Did they put in the email right?
    Because I don't know these people. They're not going to be reporting to me. I'm not part of the onboarding team. I'm just making a user.
    So we had the managers do the approvals and make sure all that information's correct, make sure they're requesting the right... We use a field called Team Name that we made custom to make sure they're getting put on the right team, the customer service team or senior customer service team, whatever.
    So someone else is double checking it and then approving it.
    And I was like, "From here, I have to be able to automate something because the information's already in Salesforce."
    And that's when I got into utilizing that approval flow to trigger an autolaunched flow to actually make my user and create the alias and create the username and update the profile based off of what was entered on the request form in my screen flow, and just physically make my user.
    Mike:
    Wow. We spent a lot of time talking about the tech part of it. I want to dive in because I feel like you conquered a lot, but you probably had to sell it. Maybe you didn't.
    Tell me about all the non-tech stuff that you had to sell. Who did you have to go to, and what were the people you met with in order to say, "Here's how I'm going to onboard users moving forward"?
    Michelle Wolf:
    So the onboarding process had already been moved to our team. And it was just that it was coming to us in a very casual way. We're getting an email request.
    So it was part of the struggle was they started emailing us individually. We were a team of three, and they would just pick which admin they wanted to work with.
    Well, if I'm out of office or I have to leave unexpectedly and forget to put my out of office on, then their stuff's getting delayed.
    And so that was the first big conversation of how do we take out that portion? How do we get them to just put it in so we can decide who does the work?
    Because if I'm heads down on a project, I don't have five minutes to go make a user. I need to be heads down on my project.
    Mike:
    Right.
    Michelle Wolf:
    So this allowed us to divvy up work more easily and really even just check our own productivity of handling these types of requests and making sure it's not one person that always gets stuck with the work because they're the one that's always being emailed.
    So that was the first thing.
    And so the three of us, we were a really tight-knit group, and we're all very aligned with not wanting to be the only human that was pinged or emailed.
    And so it was like, let's just get it to a centralized place.
    And so we just went to our manager and said, "We're going to build this. We need this to be more productive."
    And they were like, "Yeah, makes sense. Do what you need to do."
    Mike:
    I mean, that's awesome.
    Michelle Wolf:
    Yeah.
    Mike:
    Sometimes when I was an admin would happen and sometimes it wouldn't. But I do think some change has to happen that way of, "No, here's how I'm going to be more productive, and here's what I want to set up."
    Michelle Wolf:
    Yeah.
    Mike:
    So then were there... I guess what I'm getting at is, for admins that hear this and like, "Oh man, this is me," were there other checks that were already in place that you didn't have to deal with?
    There was already a check with HR or the person in payroll in terms of onboarding these people. You didn't have to go and say, "Can you..."
    Because I was the same way, to be honest with you. I would find out when I was an admin, "Oh, so-and-so needs a Salesforce license," two days after they started when HR sent out the announcement of the new hires.
    And I was like, "Hey, there has to be some process that you onboard these people to the company. Can I be part of that?"
    And I kind of had to unwind HR and figure that out because they didn't know that Salesforce was a part of this department and they didn't know that people need to be onboarded for it.
    You sound like you didn't have to deal with any of that.
    Michelle Wolf:
    We did not. That onboarding process was already handled by a team.
    And so when the hiring manager said, "Yes, we're going to offer," and they accept, they already knew what systems, what equipment they need, what systems they need access to, and then what types of permissions they would need to ask for from Salesforce.
    So like what team they were going to, so that that request could be put in. All that hard legwork was already done.
    So to those who might not have that, I think the biggest selling point could be onboarding experience.
    A lot of companies are focusing on what that hiring process, what that onboarding experience is. And as someone's starting a new job, I want to prove myself early on. I want to say, "I'm here, I'm ready to work."
    And if I can't access my systems, even though it's fully out of my control, I still feel like I'm not doing my best as an employee, as a new employee.
    So you can leverage just even the onboarding experience that they have, the equipment they need, they have the logins that they need on day one, on the day that they need it.
    Mike:
    Yeah. And you don't have to go into detail, but what are the key, I guess I'll call them, milestones in your onboarding flow that the new people get sent?
    Do you have training materials, or do you have a video that's Michelle being like, "Hi, I'm your Salesforce administrator"?
    Michelle Wolf:
    If only.
    Mike:
    I know. I always say that and everybody's like, "Oh, that'd be a great idea."
    Michelle Wolf:
    It would be. It would be.
    Mike:
    "It's just 4,792 on my list of things to do."
    Michelle Wolf:
    Exactly. When I have that free minute, I will absolutely get to that next.
    Mike:
    Yeah. And also my other two admins, because it can't just be me.
    Michelle Wolf:
    Right. "Here's your Salesforce team. We're here to support you."
    Mike:
    Yep.
    Michelle Wolf:
    So what we built into our process was, in my Flow automation, there was actually a second autolaunched flow that would close out the case.
    And this did a couple of things. One, it closed out the case so they had a complete close of the loop and updated the reason as completed by automation because a human didn't have to touch any part of this request.
    Mike:
    Ooh, that's cool.
    Michelle Wolf:
    Yeah.
    Mike:
    I like that.
    Michelle Wolf:
    Clean reporting. Who doesn't like that?
    Mike:
    I mean, for a while, I remember doing approvals or something and somebody asked me, "Well, did you actually do this or did Salesforce, the Flow do it?" And I was like, "Well, the Flow did, but the Flow ran as me." Then it marks that. But I like that you added that completed with automation.
    Michelle Wolf:
    Yeah. But we also added two email actions.
    And one was to the requester. So the individual that opened the case through the screen flow, it sent them an email telling them that the request had been completed.
    And then the second thing was, when the user record was created, it then updated the Requested For field, which was just a custom field we made on the case for a user lookup with the new user that we'd made.
    And we sent a welcome email to them and said, "Welcome to Salesforce. Welcome to our company. Here's how you access our org."
    And it had the link for the SSO. Yeah.
    Mike:
    Because at the point that the person's creating the case for you to create the user, they've already had an email assigned to them.
    Michelle Wolf:
    Correct.
    Mike:
    I like it. That's pretty sweet.
    Michelle Wolf:
    Yeah. It was just a nice clean way to close multiple loops that ended up getting started.
    Mike:
    So then, not to dig into it, and this is where I wish I should have seen your presentation, do you also have a process for adding them to... I don't know if you guys have Slack or different things like that.
    How, outside of maybe that user emailing you, do they have not necessarily an open loop, but at least a channel to ping back the admins and say, "Oh, hey, I got everything except this doesn't work, or, "I'm not seeing X," or, "How do I upload a profile picture?"?
    Michelle Wolf:
    Yeah, absolutely. So for our new hires, basically all of that was handled in their new hire training, a lot of that initial setup support.
    However, in our screen flow, we actually made it a full-service utility where when you went to launch the screen flow, you could say, "I need help with Salesforce. Something's broken." Or, "I need a new user."
    So it was this full access path to us where they could put in multiple requests depending on what they needed.
    Mike:
    I like that. And I'm assuming it's not Michelle, but you have people in the organization that do training. How much do you have to keep them updated in terms of, "Here's what the new user experience is like for Salesforce"?
    Michelle Wolf:
    As far as?
    Mike:
    Just anything. Anything that would change or anything that they may encounter, new features.
    Michelle Wolf:
    Oh, yeah. So anytime we would build any type of enhancement, we worked very closely with our training department.
    We knew if we're going to help make starter material for an announcement for the call center for X, Y, Z enhancement, training's also going to need that material and probably a deep dive hands-on demo so that they can incorporate it into their training materials.
    So any new builds like that, our training department was really involved even from early-on stages of the development because they interact with new employees, and they see that interaction differently than someone who's been here for five, 10, 12 years and knows how we use our Salesforce.
    Even just how we design and where we put things on the Lightning page, they would often give us input from a new hire perspective to ensure that we're building good things.
    Mike:
    Now, just because we're nerdy here, did you have a way of capturing that? Was that a case as well?
    Michelle Wolf:
    That was just conversations.
    Mike:
    Oh, okay.
    Michelle Wolf:
    Yeah. It was, "Hey, we have this thing. We want a demo for you. Give us feedback," type of stuff.
    Mike:
    I didn't know if you were capturing that in terms of tech debt or things we need to build, things we'd like to build, and things we need more money to build.
    Michelle Wolf:
    Yeah, depending on what it was. It was just good old-fashioned scope creep.
    Mike:
    Okay. Yeah, that usually happens, unfortunately.
    Michelle Wolf:
    Yeah.
    Mike:
    I've talked about Flow and AgentForce. I've been around now. I remember from 2006 when we finally had drag-and-drop WYSIWYG page editors to now we have... Well, I've seen agents build apps now. So I feel like I'm coming full circle.
    If you haven't already, if you were to bake some AI into your Flow, are there things that you would change or things you'd want to change and do different?
    Michelle Wolf:
    I don't know yet because I spent so much time getting it to do what I wanted it to do with all my magic formulas in that Flow. I don't even know if AI could have helped. Now, AI did help me make those formulas. But I don't know how I might leverage AI to improve this process even more.
    Mike:
    Yeah. No, that's fair. I mean, I have friends, and they always razz me a little bit because I work for a tech company, and they're like, "What'd you put AI into today?"
    And I think that's a call that admins need to make is, "Where do I need to add it?" Not just for the sake of adding it.
    I think we always talk about internally when we're creating content, "Well, don't AI wash everything." You don't have to include AI in it if it doesn't make sense because for yourself and your other two admins, that's one more thing you have to update or keep track of.
    And if it doesn't need it and you could do it somewhere else more effectively, then you should.
    Which sounds crazy, but it should be in the right places for the right interfaces, as opposed to, "Well, I included it because I could include it everywhere."
    It's like putting frosting on everything. The bacon cheeseburger doesn't need frosting just because you're a frosting company.
    Michelle Wolf:
    Yeah, exactly. And I think maybe the next iteration that could include AI would just be on the initial request, especially for individuals wanting help with Salesforce. Maybe leveraging an FAQ-type of document for the things we do get commonly asked questions about. But for the user management, I'd really have to sit down and think of how that could apply.
    Mike:
    Yeah. Or even an agent to serve up, "Here are three questions everybody asks and here's links. Do you have any other questions besides that?" And be a little proactive in terms of FAQs and stuff like that.
    Michelle Wolf:
    Yeah.
    Mike:
    So outside of email and stuff, does that seem to work okay? Or are you more leaning towards if we had Slack or anything different, we can maybe change things?
    I always worried when execs were like, "And then I want it to email me." I'm like, "You do know you have 10 salespeople. And if they have to close four deals a day, that's 40 emails on top of the eight billion you already get."
    You didn't have any executives with concerns on email velocity when you're onboarding 80 people?
    Michelle Wolf:
    Oh, no, because of the 80 people, the emails from the requesters were really going back to the onboarding team.
    And so it was a way for them to check off the list that that system is done.
    So just like they would do it for other systems or other access for Jira or their Microsoft Teams access and all that stuff. It's just closing that loop with the onboarder.
    We did have one concern when one of the managers was new, and so 20 of the new hires was theirs.
    Mike:
    Oh.
    Michelle Wolf:
    But that's not the norm. You know what I mean? It's not necessarily that all the time you're going to be hit with all of the approvals, but it did happen.
    "You're new, you're getting a full class of newbies. Good luck."
    Mike:
    "Congratulations. You now have 20 more emails."
    Michelle Wolf:
    Exactly.
    Mike:
    When you presented this, I'm curious, fresh eyes, sometimes you can sit in silence and between you and your other admins, you're like, "This is boss. I can't wait to show people."
    And then you show people, and they have a lot of questions.
    Is there questions that people had that maybe caught you off guard or you didn't think they would ask you about?
    Michelle Wolf:
    I don't think any questions really caught me off guard, but the types of questions that came up were, "How did you come up with your approval process?"
    I was lucky that my approval process was already established within my organization. You get a new hire, it's the direct manager that approves it.
    Other organizations, it's the system admin that approves that this position and title in human deserves and needs access to do their job function.
    So it just depends on how your organization slices that cake, but someone should be approving access to an org.
    Mike:
    And you know what's funny is, I probably asked you at the beginning of the podcast, but those are always the questions that I try to get out of people because especially when me and my team are building demos, the process behind what we're building, we just don't even think about.
    It's like, here's how the tech would do it. But the tech is only there to support the process.
    And nine times out of 10, everybody in the audience watches your presentation like, "Got it. Now I know how to build it. It's going to take me three months to get this process ironed out because either there's a lack of one or there's a shared understanding of how people think things work."
    And those are the questions to really ask. Are there questions that they came up with that your company hadn't figured out yet?
    Michelle Wolf:
    No, of course not. I had all the answers.
    Mike:
    Perfect.
    Michelle Wolf:
    No, I don't think so. Because my solution covered 80% or more of the situations.
    Even in the event of your admins, say your admins are responsible for giving an individual an access to the org, but then they're also responsible for giving them access to some connected program that integrates with your org, but your admins are responsible for providing that access.
    My Flow included that if a manual comment is added or if a checkbox is selected that they need this access, it adds a comment to the case using the case comments and then leaves the case in an open status, like in progress, so that your admins can go in and finish that process.
    Mike:
    Oh, cool.
    Michelle Wolf:
    And then when they close the case, it just still does the rest of that email magic to tell everybody that it's all done. So we left openings for those situations where manual changes would be necessary to complete the full onboarding from our team.
    Mike:
    That opened up a host of questions in my head. So can you create a user without going through your case and Flow?
    Michelle Wolf:
    Manually. Yeah. None of that's turned off, but we do prefer them to use the Flow.
    Mike:
    Right. I didn't know if you flagged it as, "This went outside the Flow," or something.
    Michelle Wolf:
    Yeah. The only situation where it wouldn't... No. No, we stopped making users manually because the user would still get created. It would just leave the case open. So no, it's physically possible. We do not make users manually.
    Mike:
    Nice.
    Michelle Wolf:
    Yeah.
    Mike:
    That warms my heart to know that. Well, it's always, you build the coolest solution and then the process goes around. And I remember having a manager tell me that. He's like, "Nobody's going to use Salesforce as long as they can put orders in on spreadsheets."
    Michelle Wolf:
    That's fair.
    Mike:
    Yeah, that was the truth.
    So the opposite of that, do you have an offboarding process? Is it like a similar Flow where if an employee decides to leave, does somebody create a case and that triggers your team to shut down the license?
    Michelle Wolf:
    Yeah. We actually built in a deactivate. We called it remove because our business calls it remove users, but it deactivates the user. When you choose that option in the flow, you get to use the lookup to deactivate the user. And then we also had a freeze, and I call it thaw instead of unfreeze. So we had a freeze and thaw process.
    Mike:
    I like that. That's awesome.
    Michelle Wolf:
    So yeah, we did a freeze and thaw process and we also had an update permission. So if somebody was changing teams, so somebody got promoted from customer service to sales, you can just put in the change request and once it's approved, off it goes.
    Mike:
    See, that's what differentiates what you built from everything else, because nine times out of 10, an admin will, "Okay, I'm going to build an onboarding thing."
    You're building a user management system, and you have the organization bought into it. "This is how we do this for this system."
    And it keeps a chain of custody, and it keeps a nice record for you as well. Especially the permissions update stuff, that's got to be handy.
    Are you ever asked to report out people whose permissions have changed or, for whatever reason?
    Michelle Wolf:
    I don't know that we were ever asked to report that. And the company that I built this for actually had an Apex that did all of the permission and groups assignments. It was built out with metadata and permissions because when they built that out, user access policies didn't exist.
    Mike:
    Gotcha.
    Michelle Wolf:
    So when I built it for my demo, I'm not a developer, I'm not going to build out that Apex solution, but I used the user access policies for providing those permissions and assignments for that portion of the automation and access.
    Mike:
    Yeah. I have a million more questions. I think one that people would ask. Usernames. So I don't need to know usernames, but did you put in a way to make sure that the person submitting the case doesn't have to think about the username and it's still for-
    Michelle Wolf:
    Yes.
    Mike:
    Okay.
    Michelle Wolf:
    Yeah. So I use a [inaudible 00:32:21].
    Mike:
    So you knew the answer.
    Michelle Wolf:
    I did.
    Mike:
    It took me longer to put the question together and you're like, "I already know the answer, Mike. Spit it out."
    Michelle Wolf:
    So they only gave us their first and last name, their email address, and then the identifier that we used for our SSO or Federation ID, and then what team they belonged to.
    So we knew what permissions and then who their manager was so we could get the right approval.
    Everything else was done through the formulas. And that's the tricky part. That is one of the ways in which the automation can fail.
    And it's the unique username and the unique alias. Because when you're on the new user record, Salesforce does all that magic for you. They do all the hardlifting to figure it out.
    And so instead of a one in four, because it uses the first initial, the first name, and the first four of the last names, so instead of a one in four, I made it a two and four for the alias to increase my chances of not having a duplicate.
    Mike:
    Right, because there could be a lot of Susan Smiths out there.
    Michelle Wolf:
    Exactly.
    Mike:
    Yeah.
    Michelle Wolf:
    And so what I did was I also built in on a fault path, essentially a loop. So if it failed, I would add a digit to the end and then have it try again.
    Mike:
    Oh. Would it incremental the digit?
    Michelle Wolf:
    Yes. Yeah.
    Mike:
    Well, that's smart.
    Michelle Wolf:
    And that way I could... I'd still have a chance that it's going to not work.
    Mike:
    I mean, if that poor guy hired 20 John Smiths, we're going to work that formula.
    Michelle Wolf:
    To the bone, for sure. I used Flow. I used the power of Flow to really be as hands-off as possible with it, up to and including, we wanted to keep a minimum of 10 licenses available.
    We always wanted 10 emergency licenses available. So before I create a user, I have it go get my org data to make sure I have 10 Salesforce licenses at least available.
    And if I don't, then it won't make the user. It just leaves a note on the case and leaves the case open.
    Mike:
    Saying, "You're at your minimum of 10."
    Michelle Wolf:
    Yeah. So we built in some of those custom safeguards that were special to us. We wanted that. So we put that customization in there.
    Mike:
    I like that. That's really cool.
    Michelle, you've enlightened me. I'm excited. I want to go build a Flow and onboard people and make perm sets a thing. I don't know. I feel like you probably have some solid time with an AI writing a lot of formulas.
    Michelle Wolf:
    Yes. Copilot and I got real buddy-buddy.
    Mike:
    Yeah. I mean, AI is really good at writing formulas, so thank goodness for that, right?
    Michelle Wolf:
    Yes, yes. I can do them, but those complex ones were a little on the edge of my capability.
    Mike:
    Oh, yeah. I can do with validation rules and stuff, and it requires parens. Once we get past one set of parens, I'm done. I'm cooked.
    Michelle Wolf:
    Yeah.
    Mike:
    That's it. Nope. I bow out early. I can't swim in the deep end of that pool. And I've seen people work with 15 nested statements. I'm like, "I'm exhausted reading this. How do you even know what it's doing?"
    Michelle Wolf:
    Right.
    Mike:
    Well, thanks so much for coming on the podcast and telling us about this.
    I think it's really cool. I hope you have an opportunity to share that onboarding Flow with more people and present it at more user groups.
    Michelle Wolf:
    I had a suggestion to make it a hands-on training.
    Mike:
    Yeah, it sounds cool.
    Michelle Wolf:
    Yeah.
    Mike:
    That sounds really cool. Maybe you should suggest it for TDX next year.
    Michelle Wolf:
    Yeah.
    Mike:
    Because that's a very technical, hands-on... People would love that.
    Michelle Wolf:
    Yeah. Well, they didn't pick it up this year, but I'm not sure I sold it very well. So we'll try next year.
    Mike:
    I mean, it's all in how you sell it sometimes.
    Michelle Wolf:
    Yeah.
    Mike:
    And also whether or not places have space for stuff like that. Not every track gets certain kinds of... It's a thing. That's a whole other rabbit hole within a rabbit hole that we could go to. I could do a whole series of podcasts on it, and nobody would listen to it, but I would think it would be interesting. And five people who write submissions would.
    Michelle Wolf:
    Yeah.
    Mike:
    Awesome. Well, thanks so much for being on the podcast.
    Michelle Wolf:
    Thank you so much, Mike. It was a pleasure.
    Mike:
    A big thank you to Michelle Wolf for sharing how she turned user onboarding into a thoughtful, scalable Salesforce process.
    My takeaway for admins is simple. Flow can automate the clicks, but your understanding of approvals, access, permissions, and business context is what makes the process work.
    Now be sure to subscribe to the Salesforce Admins Podcast and share this episode with somebody who is ready to get their user management out of their inbox and into Salesforce.
    Until next time, we'll see you in the cloud.
  • Salesforce Admins Podcast

    Solving Sharing Mysteries with Setup with Agentforce

    30/07/2026 | 19 mins.
    Today on the Salesforce Admins Podcast, we talk to Nikita Kothari, Senior Member of the Technical Staff at Salesforce. 
    Join us as we chat about using Setup with Agentforce to understand and manage record access.
    You should subscribe for the full episode, but here are a few takeaways from our conversation with Nikita Kothari.
    Setup with Agentforce simplifies sharing
    Why can't I see this record? It's a simple question but, as any admin knows, finding an answer can get complicated quickly. If you've ever found yourself digging through Setup pages and running SOQL queries to troubleshoot permissions and record access issues, this episode is for you.
    This week, I'm talking to Nikita Kothari, a Senior Member of the Technical Staff at Salesforce. She's here to tell us how Setup with Agentforce can help solve sharing mysteries. Using natural language questions, admins can trace access across org-wide defaults, role hierarchies, sharing rules, groups, and manual shares to figure out what's really going on.
    Troubleshooting permissions and record access issues
    As Nikita explains, permissions and record access issues are so complicated because they are affected by many overlapping configuration settings. Small changes can accumulate over time, especially in a reorg.
    Setup with Agentforce was built to help you detangle these issues with simple natural language prompts. You can put your questions about permissions and record access to an agent, instead of having to wade through 1,300 pages of Setup to figure it out on your own.
    Once you've got a handle on what the problem is, you can use Setup with Agentforce to help you implement changes and get everything sorted. And it's built with trust in mind: every write action requires your explicit approval, the agent is bounded by your permissions, and every configuration change is captured in the Setup Audit Trail.
    Plan permissions for your org
    If you're trying to figure out where to get started, Nikita recommends starting small. "It's very difficult to go back and fix something," she says, "so I would highly recommend trying any changes in a sandbox with the minimum set of users to see if it is working as expected or not." 
    And because Setup with Agentforce makes looking at permissions and record access so much easier, Nikita recommends taking advantage of it to conduct a monthly permissions review. Again, these issues accumulate over time, so an ounce of prevention is truly worth a pound of cure.
    Make sure to listen to my full conversation with Nikita for more on Setup with Agentforce and how to get sharing straightened out in your org. And don't forget to subscribe for more episodes of the Salesforce Admins Podcast.
    Podcast swag
    Salesforce Admins on the Trailhead Store

    Learn more
    Salesforce Admins Blog Post: Mastering Your Org's Sharing Configuration with Setup with Agentforce

    Salesforce Admins Blog Post: 5 Use Cases To Get Started With Setup with Agentforce

    Salesforce Admins Podcast Episode: Setup with Agentforce Makes Salesforce Admin Tasks Easier

    Admin Trailblazers Group
    Admin Trailblazers Community Group

    Social
    Nikita on LinkedIn

    Salesforce Admins on LinkedIn

    Salesforce Admins on X

    Mike on Bluesky social

    Mike on Threads

    Mike on X

    Full show transcript
    Mike Gerholdt:
    Today on the Salesforce Admins Podcast, we're talking with Nikita Kothari, Senior Member of the Technical Staff here at Salesforce, about using Setup with Agentforce to understand and manage record access. Sharing can be one of those invisible parts of the platform until someone can see a record they shouldn't or can't see one they need to. Nikita explains how admins can use natural language questions to trace access across org-wide defaults, role hierarchies, sharing, rules, groups, and manual shares. We also discuss why validation, permissions, testing, and human approval remain essential when AI helps make configuration changes. So give this episode a listen, click that subscribe button, maybe share it with another Salesforce admin who's ever asked, "Why can this user see this record?" Let's get Nikita on the podcast.
    So Nikita, welcome to the podcast.
    Nikita Kothari:
    Thank you, Mike. It is amazing to be here. I'm from the engineering team, so you'll get my lot of perspective on how we are building Setup with Agentforce on sharing.
    Mike Gerholdt:
    Yeah, that's exactly what I wanted to talk about. Let's first get a little acquainted with you. What do you do at Salesforce, and what are some of the things that you've worked on?
    Nikita Kothari:
    So it's been close to two years I'm working with Salesforce. And currently, I'm working with access control and sharing space. What pulled me in is the realization that sharing is one of those invisible infrastructure layer. When it works, nobody thinks about it, but when it breaks, it actually breaks the customer trust. And you know how customer-centric Salesforce is, its number one priority is trust. So there is lot of critical issues that we are dealing with and we are trying to make the sharing as the best place for the admins. And we love our admins and we are trying to make things better for them.
    Mike Gerholdt:
    I love our admins too. I used to be one for a while. I'd like to still think I am, but we'll see. Well, let's get into it.
    So I read your article and I'll link to that in the show notes. Tell me, I mean, before Setup with Agentforce, what did an admin have to do to answer a question of, why can this user see this opportunity and this user not?
    Nikita Kothari:
    Oh, good question. So it's the simplest way of dealing with solving the sharing's toughest problems. So just to enable the Agentforce, you don't have to do anything. It comes along with the Agentforce. So go to the setup page, search for the Agentforce agent and enable your Setup with Agentforce, and then you can start writing those questions. You don't have to know anything beforehand, that's the best part of the Agentforce setup.
    And sharing is the challenging domain, I won't deny that. It is very, very complex. So answering even the simplest question that you ask, like, "Who this person is having access for this thing," it requires to look into a lot of different domains like OWD, role hierarchy, sharing rules, sharing groups, manual shares, to see which layer actually give that access to that particular user. And looking that information, sometimes it's easier with the UI, but most of the time user has to run lots of SQL queries to get the correct answer. And previously, admin was spending hours of work and sometimes even the afternoons just to deal with that single questions. And with Setup with Agentforce, it just a minute of work. You just give prompt to your chatbots and it'll give you the correct answer within seconds.
    Mike Gerholdt:
    Yeah. I mean, boy, it used to be a lot of archeological digging. I think you called it that in the article. I know I used to have to feel like I was going through a checkbox, but tell me, I mean, walk us through a real investigation where an admin discovers that a user can see a record, they probably shouldn't. How would they use Setup with Agentforce to trace where that access came from?
    Nikita Kothari:
    Yeah, great question. So while building these actions, we particularly divide it into two different segments. First segment is the read action and the second segment is the write action. Just to keep it, things untangled, read actions will help you to investigate. When you ask a question like, "Why Nikita has access for these things?" So our agent will go into the background, it will do all kinds of research and it will come up with the best answer. "Okay, Nikita is part of this group, and these groups provide the access to this particular record." And what a write action on the hand will do, it will help you to solve that problem. Now you know Nikita is part of the particular group. You can go ahead and ask your write action, "Can you please remove Nikita from this group?" And your write action will help you to remove that particular user from that group and boom, your problem is solved within a few minutes.
    It's reliable, it's fast, and I'm sure admin can save a lot of time with these two things. And you don't need to know which action or which thing you need. You just write the plain natural language and our LLM will be able to guess where to navigate and how to solve that problem.
    Mike Gerholdt:
    Yeah. No, I hear you. I think you walked us through what a good sharing investigation looks like. But for you, is there a sequence admins should follow so that they don't just jump straight to changing configuration?
    Nikita Kothari:
    I would say I would highly recommend admin to start playing with the read action. There is no particular sequence, I would say, but mostly how the sharing is defined is like first we have the OWD, which provides the base access to the records and to the objects. And then comes the role hierarchy, then comes sharing rules, then we have public groups and queue and we have the manual shares. So at each level, sharing opens up the door for more access. So if you're going below the hierarchy, sharing will provide more and more access to the user. And if you want to close that access, it's not easier that one sharing rule will open up the access and then you create another sharing rule to close the access. It's not how it works. So in that case, you need to spend a strategic amount of time thinking how you can revoke that access.
    And sharing is accumulation of the small, small, small decisions over the time. Sometimes adding someone to the group, for the reorg, you have to do lot of things with the sharing, and every decision gets compound. So I highly recommend our admins to at least spend 30 minutes a month to refresh and reanalyze their sharing configuration to avoid the future problem. So this is basically the flow looks like, but I would say there is any of sequencing which admins should follow. It's pretty much open and admin can ask any question to our agent.
    Mike Gerholdt:
    No, I think you're right. I mean, Setup with Agentforce can do a lot in terms of explaining the configuration and then help change it. I think you really touched on that last answer of just slowing down for a second, verifying what the answer is to make sure that you're staying in control. My question to you would be, how should an admin validate what the agent tells them?
    Nikita Kothari:
    Oh, that's a good question. So for the read action, the information, we have mostly the links added to our prompts. We call it as a clickable link. So if investigation is saying that Nikita is part of this group, actually, there is a link of that group. So you can go to that group by clicking on that link, and you can actually see I'm a part of that group if you want to re-verify the stuff. So, that will give you more confidence that you know how admin is investigating the information or if admin is saying, "Nikita is part of the sharing rule and you'll have the link for the sharing rule." So you can actually go and verify whether that sharing rule contains the group or the users where it is providing that access.
    And with the write action, I think more critical is the right action. I mean, you don't want somebody, AI is coming to your system and randomly making changes to your system. So to do that, we have the validation layers. The first validation we generally come up with is for every write action, we explicitly ask for the approval, approval from the person who is making the changes. And we also have the permission boundaries, and if particular user doesn't have the permission to edit OWD, the agent won't be able to edit OWD for that person.
    And then the last part is the accountability. Every change we are logging into the setup audit trail saying that whether the AI agent did it or actual person did it. And then admin can verify it, whatever changes is made by the AI agent are trustable or not. So we will always advise admin to go and do as much as possible testing on the sandbox before making changes into the production.
    And another backup system is the Einstein Trust layer. We always say trust is our number one priority. So, Salesforce has built trust everywhere to make sure that we are not blindly making any changes, and as this is a very, very critical domain to our customers.
    Mike Gerholdt:
    No, that's great. You talked a lot about sharing, and I always feel like making a change with sharing, you want to make sure that you're doing it right. In your opinion, what is the most important thing an admin should review before making a sharing change?
    Nikita Kothari:
    So I would say, as I said before, we have some of the steps that I also wrote in my blog, that we have OWD sharing rule, rule hierarchy, and everything opens up the more access. So to close that access, it's very difficult to go back and fix something.
    So, I would highly recommend whenever our admins are making the changes, try it out first thing on the sandbox if it is working as expected or not. Or have some verification system or another set of eyes whenever you create some rule hierarchy or you're providing some access to the rule, rather than giving access to all of the user, first try with the minimal set of the user. Try with the one user and see if that user are getting right access to the right record. Because even if you fail to provide a single user a wrong access, that means that you're leaking your data. So having those, another, just starting with a small and then going into the bigger and bigger data, that would really help admin to build the reliable system.
    Mike Gerholdt:
    Yeah, absolutely. I think it can do a lot and I've seen it do a lot, but what is something that Setup with Agentforce can help with today that maybe admins may not realize?
    Nikita Kothari:
    I feel like still adoption, it's tricky because people are quite a lot thinking that Setup with Agentforce will replace their job. But I would say rather than replacing, it will provide you a lot of capabilities and it will remove a lot of overhead from your day-to-day work life, rather than going and looking into the SQLs or doing everything by yourself, just give it a try. And then you can see how much opportunity it is opening up for you to save time. And that time you can actually use for building a more structural, and because structure mattered a lot when it comes for sharing. How your roles are getting access or how your groups are getting access. And if you're just blindly following the steps and not thinking much, then you are in a trouble. So you can spend more time and thinking about, how can you better make a structure for your organization? And you can get more time to think about your business. And I feel like most of the troubleshooting cases we have covered into the Setup with Agentforce flow. Yeah.
    Mike Gerholdt:
    Yeah. You mentioned a lot, admins should get out and use it and try it, and I'm a big proponent of that. So I'll end on this question. What for you is one kind of low risk question that an admin could ask Setup with Agentforce today to better understand their sharing configuration?
    Nikita Kothari:
    I think my one of the favorite action among all of it is record access, to ask why this person is having access to this record. And you see how much it can do, it will give you the whole list of the OWD configuration for that particular record, or it will look for the sharing role, it will look for the group membership, it will look for the manual shares. And it will do all kind of investigation for you just when you type a one single natural language to your agent.
    So you can always think about someone which is having more knowledge about the setup. It's sitting with you and helping you to deal with all of the setup configuration. Because setup, again, we have like 1,300 setup pages, which is lot. And going through all and learning the capabilities of each setup action, it's difficult. So, that's why we built the Setup with Agentforce, which will give you the capability that you don't have to learn everything on the go. And you can start asking question to our bot. If it won't be able to answer, it will guide you in the right direction to help and analyze your queries or your concerns.
    Mike Gerholdt:
    Yeah. I am so glad that we have Setup with Agentforce. I feel like I could have used it 20 years ago. I know I had a lot of questions and would have to dig through my notes on org-wide and sharing and group sharing and all kinds of that stuff. So, I appreciate it. And I appreciate the article and you taking time out of your day to talk to admins and share your knowledge about sharing and setup and how we can do things better.
    Nikita Kothari:
    Yeah. I think admins are always on the top of our list. I would love to hear from our admins how they like this Setup with Agentforce, specifically with the sharing, how it is helping them or what they are looking forward to, because I feel like most of our critical projects and best solution came up with the admin feedback. And we really want to make admin life easier. We always have meetings internally, our engineering team, our product is always so much focused about thinking about our admins, thinking about the newer way to introduce some more features to make their lives easier so that they can focus on building a reliable solution. So, it was great talking to you.
    Mike Gerholdt:
    Yeah, no, I'm glad you could share your knowledge with us today. Thanks so much.
    Nikita Kothari:
    Yeah, thank you so much. And one more thing, we will be at Dreamforce. Larry Sherrill is our Product Manager. They're having a lot to share at Dreamforce. So, feel free to stop at user access booth. I'll be there too, so come and say hi and share your feedback. We would love to hear back from you. And we keep making a lot of progress on Setup with Agentforce, so stay tuned, follow our blogs, and it will be something will be really helpful in future for you guys. Thank you so much.
    Mike Gerholdt:
    Thanks again to Nikita for helping us understand how Setup with Agentforce can make sharing investigations faster without taking judgment out of the Salesforce admin's hand. And the takeaway is just really simple, use AI to uncover the source of access, validate what it tells you, and test changes carefully before they reach production.
    Now, if you enjoyed this episode, and I bet you did, I hope you did, you should subscribe to the Salesforce Admins Podcast. Share this episode maybe with your team, fellow team, user group. Oh, I like that, if you'd share it with the user group, that would be awesome. And then, how about this? Start with one low risk question about your own org sharing configuration and ask that to Setup with Agentforce. Until next time, we'll see you in the cloud.
  • Salesforce Admins Podcast

    Salesforce Superbadge Cohorts Build Skills Through Community

    23/07/2026 | 26 mins.
    Today on the Salesforce Admins Podcast, we talk to Jean Velonis, Senior Technical Program Manager at Salesforce. Join us as we chat about the new Superbadge Cohort Learning pilot program and how you can get involved.
    You should subscribe for the full episode, but here are a few takeaways from our conversation with Jean Velonis.
    Improvements to Superbadges
    I have to confess, I've always found Superbadges to be a little intimidating. They're locked behind requirements, without clear step-by-step instructions for how to work towards them. That's why I sat down with Jean Velonis, a Senior Technical Program Manager working to improve the Superbadge experience.
    The first thing Jean wants you to know is that they've overhauled the Superbadge UI. Instead of being locked behind a list of requirements, Superbadges now have a Recommended Learning section. These Trailhead modules and badges are organized into units, giving you a much clearer path to work towards your goal.
    What is the Superbadge Cohort Learning pilot program?
    In addition to the UI changes, Jean and her team are launching a new pilot program called Superbadge Cohort Learning. These sessions let you connect with other learners and subject matter experts to work towards a Superbadge together, guided by a facilitator.
    For now, the pilot program is focused on two of the most popular Superbadges. For admins, the Data Quality and Validation Superbadge gives you the knowledge you need to prep your org for AI. And if you're a dev or looking to improve your coding skills, there will also be groups for the Apex Callouts Superbadge.
    They're running both in-person and virtual versions of these sessions, so look out for them at a Dreamin' event or community group near you.
    Volunteer as a subject matter expert or facilitator
    If you already have these Superbadges, Jean highly recommends volunteering as a subject matter expert or a facilitator. When you're working with new learners, you'll run into questions and situations that deepen your understanding of the topic more than you ever thought possible.
    The other thing about students is that they keep learning. Teaching is an incredible opportunity to make strong connections that will last throughout your career. As Jean explains, two of her former students are now her go-to people when she has code or Flow questions.
    Make sure to listen to the full episode for more from Jean about the Superbadge Cohort Learning pilot program. And make sure you're subscribed to the Salesforce Admins Podcast to catch us in your feed every Thursday.
    Podcast swag
    Salesforce Admins on the Trailhead Store

    Learn more
    Sign up to be a subject matter expert or facilitator: Superbadge Cohort Learning Pilot Session

    Salesforce 360 Blog Post: How to Stand Out in the AI Era with Superbadges

    Admin Trailblazers Group
    Admin Trailblazers Community Group

    Social
    Jean on LinkedIn

    Salesforce Admins on LinkedIn

    Salesforce Admins on X

    Mike on Bluesky social

    Mike on Threads

    Mike on X

    Full Transcript
    Mike:
    This week on the Salesforce Admins Podcast, I'm joined by Jean Velonis to talk about the Superbadge Cohort Learning Pilot and what happens when admins stop learning alone and start solving problems together. We're going to dig into these cohorts and how they bring experts, beginners, and everyone together in the same room to work through real challenges, build confidence, and get comfortable being uncomfortable. Because for Salesforce admins, knowing how to troubleshoot, test, fail safely, and ask better questions matters just as much as knowing where to click. And as AI and agents become part of everyday platform work, well, those fundamental skills help admins validate what is correct, keep data reliable, and make sure that the platform reflects what the business actually needs.
    So listen in, subscribe and share this episode with an admin who learns best by rolling up their sleeves and figuring it out. Let's get Jean on the podcast. So Jean, welcome to the podcast.
    Jean Velonis:
    Thank you so much for having me. I think this is the second time I've been here, but it's been a while.
    Mike:
    I know. Well, when you do the podcast for almost 14 years now, I try not to have guests back, only if they're important like yourself.
    Jean Velonis:
    Ooh, thank you.
    Mike:
    We were Salesforce MVPs together a hundred years ago when the internet was still tubes and wires, and now we're both at Salesforce. And you're on, I would call, what, the curriculum side, the learning side?
    Jean Velonis:
    Yeah, I would categorize that. It's more Trailhead, right? So long story short, certification was my jam for so long, and superbadges were part of that. But over the last couple of years, we've decoupled from certification. We're still with Trailhead and we're still considered an assessment, but we don't have all the guardrails of certification on us anymore, which is really exciting.
    Mike:
    Gotcha. And just for reference, if anybody thinks they might have met Jean at a Dreaming event or a Salesforce event, you tend to usually have purple hair and a bedazzled Ranger hat. Is that an accurate description?
    Jean Velonis:
    These are facts. These are facts. I've had purple hair probably since six months of coming into Salesforce. And if anybody knows the famous Chris Duarte out there, she taught me everything I know about bedazzling. So I made a Ranger hat.
    Mike:
    Yeah. A lot of people bedazzle now because of her.
    Jean Velonis:
    Yes.
    Mike:
    Well, let's talk about this new Superbadge cohort learning pilot that you've kicked off because I think you're trying to bring the best of both worlds together.
    Jean Velonis:
    Absolutely. This isn't a new concept either. I'll just throw that out there. We had some amazing trailblazers before the pandemic and even through the pandemic doing Salesforce Saturdays or Salesforce Sundays and they would get together in person or virtually and work on Trailhead. So this is kind of piggybacking off that concept and really bringing some of the community magic to superbadges because I think we can all look at a superbadge and be like, oh, that's kind of intimidating. There's no step-by-step instructions. This looks really hard. There's multiple steps to it, and that just looks hard and I don't want to do it. But the cohort learning brings a facilitator, like a community group leader or a Dreamin event person to come in and help bring people together virtually or in person and work on a Superbadge together.
    And we've been running a couple of pilots of these. We did one at TDX and WITness Success in Indi. And it's been really successful in person just because you can pair experts and newbies together at a table and make people really uncomfortable, and then they start talking to each other and learning from each other. And I think that's what gets really excited about doing this cohort learning. And then we've done a couple of virtual events as well where we've brought community group leaders, kind of like train the trainer of like, here's how you should run this virtually to be successful, because that virtual is a little bit different beast. It's really easy to hide and stay on mute and turn your camera off where we really try and get people excited to share their skillset with each other.
    Mike:
    Yeah. No hiding in the dark corners. So I really like the idea of this. I've always really enjoyed Trailhead because I'm the type of learner that likes to do it at my own pace. Sometimes I even crazily go back and redo a badge just because I feel like if I've rushed through it, did I really learn it or was I just trying to get it done? And when I'm really trying to learn it, I really take my time. I will agree with you, I've written superbadges. I also enjoy the freedom. They're kind of like, "Here, go, do. " And you're like, "Oh yes." It's almost like the days of driver's ed when you get out from behind the desk and you finally get to drive the car in the real world. It's a little more of trying things out. So are these cohorts that you're doing now, are they open to any superbadge or are they just specific ones?
    Jean Velonis:
    That's a really good question. We looked at our whole library of Superbadges and we wanted to pick one for admins and one for developers. And that doesn't mean it's just if you have that skill set. It's more of like, here's two of the main roles we see in the community. So we have data quality and validation, which is really for anybody prepping you for this agentic ecosystem that we're in, cleaning up your org.
    Mike:
    I mean, to be honest with you, that's what we've needed to do this whole time. Even before AI, it's sweeping the floors, you know?
    Jean Velonis:
    Yeah. I mean, it's been that way for a long time. I think I made my whole Salesforce admin career of going in and cleaning up orgs, to be honest. So that was a great place for us to start. And then now we've started looking at the developer side of it and we picked Apex Callouts superbadge for all of our developers. And I was very intimidated by trying to put together a superbadge in a box for that cohort because I'm not a developer. But going through this process, I'm like, "You know what? I think I can actually do this," And that's because of all the great learning badges on Trailhead and being able to go at your own pace. Because that's a whole nother skill set for an admin to try and figure out, right?
    Mike:
    Right. I've often thought of, this is just how Mike's brain works. If I had children, I would for sure name one of them Apex because then you just gave them a shout-out.
    Jean Velonis:
    That's hilarious. I would've never thought-
    Mike:
    That's how I work. My brain today is like, "Oh yeah. Hey, did you hear you were mentioned on a Salesforce podcast?" "Of course I was. I'm an Apex Callout."
    Jean Velonis:
    I'll tell you a weird secret. I do put my children's names in superbadge content. All of us over here under the superbadge team put little-
    Mike:
    Easter eggs?
    Jean Velonis:
    Easter eggs, yeah-
    Mike:
    Yeah, I love it.
    Jean Velonis:
    ... out there. It's either in the org or it's in the content. We're all moms over here, so we would like to give our kids a shout-out.
    Mike:
    Well, I will see your Easter egg and I will call your Easter egg. In almost every admin keynote demo, we have put our pets' names.
    Jean Velonis:
    I love that.
    Mike:
    So you can go back and figure out whose pets were whom. The only time, the only exception was we had Einstein Voice rollout and my dog's name was yet to be used and we couldn't use it because it wouldn't recognize it. It was too hard to say. And so we had to go with something easy and punchy with hard consonants in it. So anyway, yes. I think there should be, I'm sure there is somewhere, a whole forum of Easter eggs found in Trailhead material.
    Jean Velonis:
    100%. And I think that's what Trailhead is, where it's the weird, it's the hanging out, it's the learning something new, it's the being uncomfortable. Because it really is, learning can be really uncomfortable.
    Mike:
    I mean, it exposes a weakness and people don't like feeling weak. It's also the thing I always think about whenever I was doing training because you're changing something. And the person that told me how to do training gave me a very well-rounded, concise piece of advice, which is people don't like to go to work and feel stupid. And when you change something, even in a CRM, that's what that comes from. And people don't like to feel stupid. And I feel that way. You change something, you're like, "Oh, this was here yesterday. Why isn't it here?" And you blame yourself and that's not the point. You do a lot of training. So let's go through just some scenarios of I'm a new Salesforce admin. I stumbled across this podcast. Also, hello. You have a lot of episodes to catch up on. That's okay. You have a lot of time. What should they do to prepare to come to one of these learning cohorts?
    Jean Velonis:
    I mean, the easy answer is get on Trailhead and start earning badges, that's number one. Step two is take a look at the new look and feel for superbadges and that will bring you to our recommended learning. It used to be required to unlock the superbadge, but we've just now come onto what I would say the Trailhead UI. Superbadges are put into these units now where the first unit is like, let's get ready. Let's get your developer org. Let's do the recommended learning. Let's connect it to your superbadge now. That's all a little bit different than what we used to do with superbadges. You had to unlock it and then you had to go down all the way to the bottom of the page to hook up your org. Now it looks like a regular module or badge, which is nice because as somebody who struggles with reading and keeping my place on Trailhead, this new guy is really going to help with that.
    But also doing the recommended learning I think is key even though it's unlocked now and you don't have to do it. I will tell you I am the first person to start doing something and being like, "Oh, I have no idea what I'm doing with this. Maybe I should have done-"
    Mike:
    I should have done those recommended modules.
    Jean Velonis:
    Yes. And then I will have to go back and learn and figure things out. I did that with the prompt template superbadge. I thought I knew what I was doing.
    Mike:
    No.
    Jean Velonis:
    I did not. And that's falling, that's failing forward. That's realizing I don't know what I'm doing. Let me go figure this out and then come back to it. So I think that's step number two. Go and read through the superbadges, look at them, look at the recommended learning. And then if you see that there is a Dreamin event or a community group doing one of these superbadges, join them. Even if you've done the superbadge, that's okay. You can go help the other people that are there.
    Mike:
    Oh, I almost think that would be the next best thing after doing a superbadge is going and volunteering to help train. Because never will you ever learn more about something than when you have to train somebody about something or walk around the room and answer questions. You're like, "Hey, I didn't run into that when I was doing mine, but let's figure it out." And it's super fun because then you're like, "This wasn't a problem for me, but now it's a problem that I get to work through."
    Jean Velonis:
    Yeah. I mean, bringing you all the way back to SABWA.
    Mike:
    Oh, sure.
    Jean Velonis:
    Call out, Mike. I mean, geez. Yeah, that is my favorite thing to walk around, especially I live in these superbadges every day. Our team builds them. We maintain them. We have to deal with all the product changes that are very quickly changing and trying to keep up with everything. So being able to walk around the room and see how trailblazers are doing things, that not only helps me figure out, okay, here's some of the common pitfalls or where people are getting stuck and I can write some hints to help, but also maybe we don't do that in the next superbadge or maybe we call it out in a different way or let's go update the help article and call this piece out if somebody's getting stuck somewhere. So it's super helpful. But also you get to meet a ton of different people, which we do virtually every day, but it's easy to hide behind the keyboard again. And to be able to connect with somebody and see their aha moment of where they're like, "Yes, I figured this out," that's super gratifying.
    Mike:
    Oh, that's almost the time that you make a friend.
    Jean Velonis:
    A best friend.
    Mike:
    Yeah. I mean, because you're always going to be like, "Well, let's continue chatting while you work through this." And then the next thing you know, they're building Apex Callouts, and you're like, "Oh, I didn't get that far." And then they're teaching you stuff. I promise you it'll happen.
    Jean Velonis:
    It will happen. I can say 100% certainty it will happen. I have two people that I call on all the time or that I met through a conference or doing something, and I'm like, "Okay, I know this person knows code and I know this person knows flow. I'm not good at those things, but I can text or call or Slack and be like, I'm stuck."
    Mike:
    Right. So I mean, I have a thousand questions, but let's go to the opposite end of that where if you're a community member, maybe you're a user group leader or a Dreamin event person and you're like, "This sounds like a super fun thing for me to include in my agenda," What would their steps be for possibly including, I know it's in a pilot, but for including this or what's your vision for it moving forward?
    Jean Velonis:
    Yeah. We have a facilitator signup forum-
    Mike:
    Sweet.
    Jean Velonis:
    ... which I'm sure you would be happy to put that in the bio or the show notes.
    Mike:
    It is in the show notes as we speak.
    Jean Velonis:
    Perfect. But yeah, just signing up to raise your hand to be a facilitator is huge. Because I'm going to have this superbadge in a box ready very quickly for people to take to a pilot. I have two Dreamin events that are already wanting to do this in August and a community group that also wants to bring it to their local people. So signing up to be a facilitator and doing this on your own, love that. And I wish I could go to every one of them, to be honest. I looked at a couple of them and I'm like, "I might be able to make this work and just show up." But there's also a piece in that form too to sign up to be a subject matter expert and help if there's somebody locally that wants to do this. And selfishly, I put that in there that if you want to help us build superbadges, that would be awesome too.
    Mike:
    Right. And this sounds rhetorical, but it is honest. They should have probably already completed that superbadge that they want to facilitate or host.
    Jean Velonis:
    I mean, I'd advise it. And with the new UI, you can redo a superbadge. You can retake it now. So you can do the superbadge over.
    Mike:
    To refresher, because maybe you haven't done it in a while and want to see what's new.
    Jean Velonis:
    I mean, the facilitator that did WITness Success told me she still had her notes when she originally did the Apex Callouts in 2017.
    Mike:
    Wow.
    Jean Velonis:
    Right?
    Mike:
    I probably have notes from somewhere of 2017 I have nowhere. That's awesome.
    Jean Velonis:
    No, that notebook's gone.
    Mike:
    Yeah. I always think of admins listening to this and I don't want it to be a pitch session for your cohort, but this is really a neat way to get involved with the community. From all of your work, and this is just stepping out of your role and what you're doing in this superbadge cohort. Out of all of the work that you've done at Salesforce and what you create for Trailhead, what are some of the biggest themes that you run into that really, when that light bulb turns on for an admin, they suddenly just become, I don't want to say instantly become successful, but they really start to click and feel confidence and have that aha moment?
    Jean Velonis:
    I think being a Salesforce admin for such a long time, being able to fail and problem solve is probably the best skill you can have. You can learn any technical skill. I can go into a dev org and break things and figure out how products work. But if you don't know how to problem solve through something, getting to that aha moment is going to take you a long time if you're too afraid to break something. And I have broken things. And I think I've told you, I've deleted records from an org before and went, "Uh-oh, how do I get those back?" So that is one of my favorite things is to go into a playground or dev org and just break it, pull things apart, see how it works and be like, "Okay, I know where I want to go, but how do I get there? And I don't know how to get there, but if I go in and break everything, I'm going to learn a lot more than if I follow step-by-step instructions of how to do something."
    Mike:
    Right. If it works out perfect the first time.
    Jean Velonis:
    Yeah. What did you learn? Oh, I know how to do that. Okay. Well, what's next then?
    Mike:
    Do you find that you have to remind people that it's okay to fail when building and it's okay for things to not work the way you want them to the first time?
    Jean Velonis:
    Yeah. And I mean, that's how we build superbadges. I mean, we have all these SMEs and we look through different use cases and we go into an org and build it out and we're like, "Well, that's not going to work for this unit," or, "That's not going to work for this use case," or how do we find those different tasks to lead the witness basically in the challenge to get to where we want them to go, but without telling them? And you can do it 97 different ways. There's not necessarily always a right way to get there.
    Mike:
    Right. I know I've sat down. We used to have, it was Dreamforce long, long time ago. And I was paired up with Josh Birk and we were helping a customer through a situation. And it was interesting because both he and I came up with a solution. Both he and I came up with a very different path to the solution. Mine was using, at the time, Flows, and his was using some code and some triggers. And the customer's like, "But which one's right?" And we're like, "Both of them." I mean, never could you ever run into a situation where both solutions are equally correct. It's based on what you want to maintain and your knowledge.
    Jean Velonis:
    100%. And now you also have this agentic thing that will try and tell you the right path to go and you can be like, "Well, I don't want to do it that way." And it's like, "Oh yeah, you're right. Let's try it this way." So I think even having that fundamental base of an admin or a dev is really going to serve you well in this ecosystem. So problem solving, having a foundational skill set, and then also knowing where you want to go and problem solving your way to get there.
    Mike:
    Right. So let me ask you, you've brought up agents and AI sometimes intentionally, sometimes unintentionally, but I mean, it's definitely something that it's our every day now. From your perspective as building a lot of content and in the learning space, what is the most important thing you think admins should learn about AI and agents? I
    Jean Velonis:
    I think the most important... Well, there's two. Learning when to trust that the AI is telling you the right thing and knowing how to ask the prompts and the questions. Because you may not know where you want to go, but if you have your fundamental base of the system, you can ask it the right questions to get you where you're going. And as somebody who struggles with writing content, I know where I want to go, I know what the tasks are for the superbadge. And I can say, "Okay, now help me write an error message," or, "Help me write a hint for a help article that's going to help them get unstuck." And you can ask AI that too. You're like, "Hey, I'm using this Flow element. I'm trying to go here and make this system do this. It's not working. Help me untangle this."
    Mike:
    Right. Help me. Teach me, don't tell me.
    Jean Velonis:
    That's key. Teach me, don't tell me. I don't need step by step.
    Mike:
    I do that all the time with Wordle. Don't tell me the answer, just help me figure out what this word is. I'm stuck. Jean, last question because I know you have to go. It's 2030 and the Superbadge Cohort Learning program is out of pilot. What does it look like?
    Jean Velonis:
    It looks like all of our trailblazers getting together, helping each other learn something new, experts and newbies and everybody in the middle taking something away from that hour or that day that they spent with each other and everybody having their own aha moment. Whether it's I helped somebody get unstuck or I got a new superbadge or I made a new contact or I'm out of a job and I made this whole partner and I handed them my resume, those are the things that make the community go round. Those are the things that makes learning so important. And it's okay to break things.
    Mike:
    Right. Very well. Very well said. Thank you, Jean, for being on the podcast.
    Jean Velonis:
    Thanks, Mike. Happy to be here.
    Mike:
    Big thank you to Jean Velonis for joining us and reminding us admins that getting stuck is not the end of learning, it is usually where the useful part begins. Now, whether you join a cohort, you facilitate one, or you know what, you simply just help another Salesforce admin work through a challenge, teaching and problem solving are powerful ways to strengthen your platform judgment. Be sure to subscribe to the Salesforce Admins podcast. Share this episode with somebody who is ready to learn and really earn that next aha moment. Until next time, we'll see you in the cloud.
  • Salesforce Admins Podcast

    How Can Admins Reduce MFA Friction in Salesforce?

    16/07/2026 | 32 mins.
    Today on the Salesforce Admins Podcast, we talk to Jay Hurst, Senior Vice President of Product Management, and James Ferguson, Senior Director of Product Management, at Salesforce.
    Join us as we chat about MFA step-up authentication and what it means for Salesforce Admins.
    You should subscribe for the full episode, but here are a few takeaways from our conversation with Jay Hurst and James Ferguson.
    Step-up authentication protects sensitive actions
    Starting next week, Salesforce is requiring all users to use Multi-Factor Authentication (MFA). If you're a privileged user like, for example, an admin, you'll need to use a phishing-resistant MFA. That's why I sat down with Jay Hurst, VP of Product Management, and James Ferguson, Senior Director of Product Management, to talk about why these changes are vital to protect your org's data.
    The first thing to know is that AI is making it easier than ever to launch targeted phishing attacks at scale. So while the MFA requirements provide a good first layer of protection, we want to make extra sure you are who you say you are before you're allowed to perform certain actions, like downloading a large number of records or running a big report.
    Phishing-resistant MFA uses a passkey, like a fingerprint or facial recognition biometric, to verify that it's actually you and not just someone with access to your email account.
    Balancing security with user friction
    As Jay and James acknowledge, these changes will add some friction to your users' experience. However, with the pace at which these kinds of attacks are evolving, it's more important than ever to get serious about your security posture.
    "We're trying to introduce a little more friction right now so that people start to think," Jay explains, "and start to build those habits of understanding when they're doing something that potentially could be considered a malicious attack, such as downloading that All Opportunities report."
    They're also building out compensating controls that should make things easier in the future, allowing you to trust users from a certain IP range, for example.
    Security is a journey, not a destination
    The most important thing to realize is that these requirements are about more than just jumping through some extra hoops. Phishing and man-in-the-middle attacks are growing more and more sophisticated, and you need better protections than "Well, that hasn't happened yet."
    Instead, James and Jay recommend viewing this as an opportunity to partner with other stakeholders in your org to develop a comprehensive security plan. As Jay says, "Security is a journey, not a destination. What is 100% secure today is not as secure tomorrow." The trick is to develop a security-focused mindset throughout your business that will protect you now and in the future.
    Make sure to listen to my full conversation with Jay and James for more on step-up authentication and how admins can reduce friction for users. And make sure you're subscribed to the Salesforce Admins Podcast so you never miss an episode.
    Podcast swag
    Salesforce Admins on the Trailhead Store

    Learn more
    Salesforce Admins Podcast Episode: What Are Security Essentials for Salesforce Admins?

    Salesforce Admins Blog Post: Securing Your Org: From Reactive to Proactive

    Salesforce Help Article: Prepare for the upcoming Step-up Authentication requirements on Report Actions

    Salesforce Help Article: Prepare for MFA Enforcement for All Employee Users

    Salesforce Help Article: Prepare for Phishing-Resistant MFA Enforcement for Privileged Users including Admins

    Salesforce Help Article: Security-Related Product Updates to the Salesforce Platform: User Identity, Data Protection, and Access Controls

    Admin Trailblazers Group
    Admin Trailblazers Community Group

    Social
    Jay on LinkedIn

    James on LinkedIn

    Salesforce Admins on LinkedIn

    Salesforce Admins on X

    Mike on Bluesky social

    Mike on Threads

    Mike on X

    Full show transcript
    Mike:
    This week on the Salesforce Admins Podcast, we're talking with Jay Hurst and James Ferguson from Salesforce Product Management about MFA step-up authentication and what it means for Salesforce admins. As you know, security isn't just a front-door login decision anymore. It's about protecting sensitive actions, understanding risk, and designing systems users can trust.
    So Jay and James are going to help us unpack phishing-resistant MFA, compensating controls, IP ranges, SSO, and why these changes matter in a world where data, automation and AI are all working together. For us Salesforce admins, this is a chance to think beyond features and really look at how we steward the entire system. So listen in, click that Subscribe button, and of course I would love if you could share it with fellow Salesforce admins or, hey, you know what? Let's make some friends in that security team. So with that, let's get Jay and James on the podcast. So Jay and James, welcome to the podcast.
    Jay Hurst:
    Thanks for having us, Mike.
    James Ferguson:
    Great to be here.
    Mike:
    Absolutely. Jay, let's start off with you. We kind of want to get to know a little bit about you, and James, we'll call on you second, but before we get into our topic today, can you just tell me a little bit about how you got to Salesforce and what you do?
    Jay Hurst:
    Sure, yeah. So I have been with Salesforce for almost 22 years now. I started in our customer support department, one of the first 12 phone support reps here at Salesforce. Did that for a couple years and helped found our Tier 3 organization in support. Eventually moved over to our customer-centric engineering department, stayed in there for a while. And then in 2012, had an opportunity to join the product management group for platform, and I moved over and ran a team called Force.com Canvas. And for the last, I guess, 12-ish years now, I've been kind of weaving my way upwards through platform. Currently, I lead our platform services subcloud, so all of the core foundational pieces of platform that you might think of are schema and metadata, APIs, eventing systems, connectivity systems, and also our identity area, which is what brings us here today to talk about MFA.
    Mike:
    Yeah. Boy, flashback. You called it the Force.com platform.
    Jay Hurst:
    Well, that's what it was called back then.
    Mike:
    I know. I know.
    Jay Hurst:
    And I can't remember all of the names we've had for it.
    Mike:
    Oh, that's okay. I'm sure there's a website that tracks all of them.
    Jay Hurst:
    I'm sure there is.
    Mike:
    James, fill us in. How'd you get to Salesforce, and what do you do here?
    James Ferguson:
    Well, I am, I guess compared to Jay, one of the newer members of the team. I've only been at Salesforce for about 16 and a half years, almost 17 years. Pretty much entirely on the platform product management side, working on various things people know and love like sharing and big objects and event monitoring and those things. And most recently I've taken over responsibility for the identity product team, responsible for all the login and auth and SSO and all of the wonderful things we'll talk about today.
    Mike:
    Oh, wow. Okay. So then just to be clear, I'm actually the newest person on this call. I've only been at Salesforce for a little over 12 years now, so I guess I still have my rookie stripes.
    Jay Hurst:
    Combined we're almost at 40, or just over 40.
    Mike:
    Yeah, combined. We almost get our AARP discount, right?
    Jay Hurst:
    Yeah, exactly.
    Mike:
    Jay, let's kick off. I know I did a podcast ... and I'll link back to it ... not that long ago with Laura Pelke talking about some of the new things that were coming out, and of course security is always big on admins' mind. She did a wonderful job of explaining step-up authentication to me, which was basically the airport analogy of you have to show your ID to get in and then you have to show your boarding pass to get onto the plane. I thought that really made sense to me, but let's talk about the new authentication that's coming out, if you call it that, and the new step-up concerns that Salesforce admins have.
    Jay Hurst:
    Sure. So I think as we move into the continued proliferation of agents and AI across the industry, security is obviously top of mind for a lot of our customers and for Salesforce as well, specifically because we have to help protect our customers. And so when we're thinking of that and how we ensure our customers' data is protected, with step-up authentication, it's really focused around in that same analogy, making sure you're providing your boarding pass at the right times when you're doing things. So just like you need to show your boarding pass when you go through the TSA gate and when you're on the plane and probably to the gate agent after you're on the plane, when you're doing certain things within Salesforce, we want to make sure you are who you actually are and your session hasn't been compromised.
    So when you're doing certain higher sensitivity-type actions such as I want to download 10,000 records out of my system, maybe run a report, putting that end user through another verification of, "Hey, is this actually you? Prove it with your step-up," so that we have that confidence that we can release the records. And so this kind of helps prevent some of those man-in-the-middle phishing attacks where somebody gets you to log in and then steals your credentials or steals your session in the background. So it's kind of that second or third or fourth level of protection in the runtime.
    Mike:
    Wow.
    James Ferguson:
    I think that's an important shift that's worth calling out, because it's no longer about just putting a stronger lock on the front door and making sure somebody has better passwords, or even the later stuff, the more recent stuff with verification. But it's when sensitive things happen, we need to do a little extra even once you're inside the airport, if we want to continue that analogy. And so it's a shift from that front door to moving forward.
    Mike:
    Yeah. James, help me understand that a little bit more, because I think one of the things that admins always fight is user friction. How hard is it to do something? And now we're introducing something when it could disrupt their flow of work, but it's for a good reason.
    James Ferguson:
    Exactly. I would say that we are constantly balancing that. We're constantly balancing the need for security with the friction it does. And so we aren't expecting to do every click, for example, but just when you're exporting data from a report, which is potentially pulling a large amount of data out, we want to make extra sure. We're looking at some other things in the future around maybe when you're an admin changing some security configurations, we want to make sure you are who you are. And frankly, you see this more and more even in consumer websites where sometimes you're asked. If you're going to change a phone number, change a thing, you need to go back and sort of double-proof who you are. But it is a trade-off. It is a trade-off.
    Mike:
    Yeah. It's like once you're logged in, it's, "Oh, if you're going to change." I was trying to order tacos the other day through an app and I needed to update my credit card. And then right after I did that, they're like, "And you need to put your password back in." I'm assuming that was kind of the same situation.
    James Ferguson:
    Kind of the same situation.
    Jay Hurst:
    Yeah, exactly. Exactly. Yeah. And the other thing I'll add to this too is on the friction point. We always have to balance that. Like James said, we don't want people to become overly frustrated and not want to use Salesforce because it has too much friction. But the reality is over the last 20 years, we've edged so far on the line of not causing any friction that we've led admins down the path of not having that understanding of what their users are doing, and really not getting into that proper security-conscious mode. So we're trying to rubber band a little bit back on the other side, introduce a little more friction right now, so that people start to think and start to build those habits of understanding when they're doing something that potentially could be considered a malicious attack, such as downloading that all-opportunities report. So starting to get customers to think through that while we are continuing to build out what we call compensating control.
    So the end goal here is not to provide friction and it's not to force you to do these one-time passwords for everything you need to do in the system. It's to give admins that layered capability of saying, "Well, if I have these five or six different controls I can put into place, then they can kind of compensate for one another." So where the most friction might be having to open up your email to get that one-time password to do the step-up, maybe we can compensate that through things like having a trusted IP range or already having a phishing-resistant authentication put in, or other controls that we will layer in. So we ultimately get to a posture where the admin can both reduce friction while choosing the proper set of controls for their needs.
    Mike:
    Yeah. No, that makes sense. You mentioned phishing-resistant MFA. Can you help me explain that if somebody's never heard that before?
    Jay Hurst:
    Yeah. So maybe I'm going to try and wiggle this airport analogy in. If we think way back in the day when you had your IDs, before REAL IDs and all of this, you didn't actually have good authentication on them. You might have a really bad picture, or in some cases IDs didn't have any pictures on them. They just had your name and your information, but they were accepted. Now, the problem with that is anybody could steal it if it doesn't have your picture, and they can pretend to be you.
    So phishing-resistant MFA is kind of that same thing. Where a normal MFA might be a one-time password on your phone where you get that push notification that says, "Hey, your code is 123456, enter that code in," that's great because it means you have to have your phone in order to get that one-time password, but it's not as secure because it's sent over SMS. It doesn't really verify that you are who you say you are. It's only that you have access to that phone. Phishing-resistant adds another layer on top of that, so it's not just over SMS or in an app. It would be through what are called passkeys or other more cryptographically secure passes. So think of your face ID, your touch ID, some of those passkey-type implementations that you might see, where it's not just getting a code, but you have to unlock a vault that has your information in it and then you provide that information out.
    So it's taking it from that ID that anybody can use if they just happen to steal your wallet into more of a REAL ID that also has some biometrics attached to it. So you can actually guarantee it's not just that you have the thing, but you have the thing and you are the person that should have the thing that identifies you. And so that's what we're implementing today that's starting to roll out tomorrow in production. We've already started pushing it into sandbox for admins where we want all of our administrative users across the system to enroll and use these phishing-resistant MFA capabilities, so that they're more secure.
    Mike:
    Yeah. I never even thought of that. All the time there's apps I log into and they send me a one-time passcode and I'm like, "Well, of course I have access to it." Never did I think that, "Oh, what if somebody already has access to my email, requests that code, and now they're essentially spoofing me?" And it never dawned on me until you think of, well, they're not really verifying that it's you, Mike. They're just verifying that whoever requested that code also has access to your inbox. And you're like, "Oh."
    Jay Hurst:
    Exactly. And that may not be a nice person.
    Mike:
    Right. So James, what are some questions that admins are asking online that we can kind of help answer for them, or equip them for when they get this rolled out to them?
    James Ferguson:
    They're certainly asking questions about phishing-resistant MFA versus regular MFA and the different sort of authenticators that are out there. I'll shift this around a bit. One of the things they aren't asking about, it's actually something that Jay mentioned in passing, which is the alternate controls. And for things like step-up, if you have login IP ranges on the org or on the user profile, or there's some session settings which force you to always be coming from the same IP address in your session, which is the case for most of us who are at a laptop at work or whatever it is. Those avoid step-up entirely because we have more certainty about who you are and where you're coming from. If your session's bouncing between Eastern Europe and Middle East and North Carolina and keeps hopping around, we start worrying more.
    So you can do some things around IP ranges, which takes that friction away from the user altogether, and so those are some of the things that I would encourage admins to look into. Now, sometimes it doesn't work because of mobile providers or other network infrastructure, but it's also potentially a low-calorie way of really sort of avoiding at least the step-up part. They'll still have the MFA requirements.
    Jay Hurst:
    And one thing I'll add to that. When we add these types of controls to ... admins are human like the rest of us and we always want to make it as frictionless and easy as possible, but we don't want to trade off the security for it. So IP ranges specifically have been a little bit of our bane for the last six months, because we have a lot of customers who have said, "Well, I will just put in the entire internet range of IPs and go 000 to 255, 255, 255, 255. And then no matter where I'm coming from, I'm not going to get challenged and it's going to be great." And that works, or worked, but it's not secure. And so we don't want to trade off security for just checking the boxes. There are reasons for us doing this.
    Now, with that one specifically, we have put in changes in place where we won't let you use such a broad internet range to get around it in that respect, where you actually have to put though into like, "Well, what is the internet range that I'm actually coming from and using?" And we have some friction still with that, I would say, with admins using very global deployments or salespeople that travel around a lot and using different VPNs. So we're working through that as one of those compensating controls rather than the primary control. But again, it is up to all of our admins to really think through.
    We don't want you to just do the check the boxes that we're telling you to check because we want you to check a box. We really want you to think about these changes and what it means to your organization, why we're actually trying to implement these, and ultimately determine what makes the most sense for you and your company. And include your security officers and your CISOs to really validate what meets the requirements that your company has, so that everybody is protected both from a security perspective and ultimately a legal perspective as well.
    Mike:
    Yeah. No, absolutely. I mean, we did a security day at TDX, our team did, and we had a CISO in there and a Salesforce admin as one of the kind of breakout topics, and they were in lockstep with each other, and I've always said that. I remember the instance I was managing, once it grew beyond 10 users, I was like, "I really need to figure out what our security posture is and who's in charge of this, who sets password complexities," at the time and stuff like that, and it's not adversarial. It's you want to be in alignment with what the rest of the company's doing and also fall in line if there's a SSO requirement. Boy, I was quick to jump on that, because it also made logging in simpler for my users.
    Jay Hurst:
    100%, and that's the other side of this. All of these things do play with SSO. If you have implemented SSO that has phishing-resistant capabilities already built into it, great. We will take advantage of that from the Salesforce side. We'll trust your provider. We'll trust that your security team has already set up what is needed for your company and we'll let you log in. So we don't want to add these additional duplicative type of controls for you, but we also recognize that a lot of our customers, maybe they're smaller customers, maybe they're not the enterprise size of Salesforce and don't have as structured of a security posture. So in those cases, we want to partner with our customers and really help them define what this should look like when they're thinking about internet security and their data in the cloud.
    Mike:
    Jay, I'm going to continue with you because James brought up a really good point. I was thinking of, "I'm going to ask him the common questions that admins are asking online." And James, you flipped the script, and it's, "Well, here are the questions that worry us that they're not asking." Jay, I'd ask kind of the same question to you, is you've seen a lot of the questions that our community's asking online. What are the questions they aren't asking that you really hoped they would ask, or you're there to provide an answer for?
    Jay Hurst:
    Yeah, I think the biggest ones, James talked about the compensating controls. That's a good one. I think a lot of our customers, as they're approaching it from the first standpoint is really they're looking at this as a Salesforce tax. They're really looking at it as like, "Oh, gosh, this is another thing Salesforce is putting me through. I don't know why. Why don't you just let me get my job done?" That type of attitude, which is completely understandable, but I do think one of the things our admins aren't seeing at that first cut is really the threat landscape that exists out there. I think if you haven't been attacked, if your org hasn't been compromised, it's very easy to fall into complacency and just think, "Everything's perfect, I'm secure, nothing's going to happen." And like everything, security and protection is a spectrum and it's a journey. You are never 100% perfectly ready for every outcome, and you also can't assume that what worked yesterday will continue to work tomorrow.
    So what I would love to see more of our admins and customers look through is how do I build the security and the continuing advancement of my security posture into my day-to-day, into my development scenarios, into my admin scenarios, where the first thing we should always be thinking about is, "Is this change I'm doing helping or degrading my security posture? And if it's degrading, how do I increase it? What do I do to make it better?"
    So I would love to get to a point where our very wonderful and vocal admins out there are also pushing us to do even more things to help protect them. What are the other controls that they're seeing across other enterprise systems that they want to take advantage of? How can Salesforce make it easier for you without lowering that security posture? How can we make it so that the friction can be lowered faster because you acknowledge the acceptance of the controls, or something like that around really getting back to a true partnership with more of our customers that I wouldn't say we've lost, but it's easy to forget about when you're focused on the headless 360s of the world or how can I get more agents into my system. And we also still have to think about, "And how do I keep it protected and managed?"
    Mike:
    Right. Yeah. I mean, it's more people in your house, but also making sure that everybody shuts the door and locks it.
    Jay Hurst:
    And wipes their feet.
    Mike:
    Right. Takes shoes off.
    James Ferguson:
    I think Jay also touches on what maybe I would consider the elephant in the room, because I think, when going back to the original question you asked in terms of what are admins asking, most of them aren't asking the why. Most of them acknowledge the value of these things and the need to do it, but they do push back on the why immediately and why under these compressed timelines and why, and sort of those kind of questions. And I will acknowledge that the rollout of some of these controls has not been as smooth as we all would've hoped, and so there's been some schedule things bouncing around from a timing perspective, and so we're definitely working on all of that. But it does play to that level of risk, and these are the things we really felt we needed to roll out sooner rather than later, and so that's why some of these timelines are compressed.
    I will add another, the flip side of that, to your point about what should admins be doing. We do find when we give notice, of like advanced notice of asking people to change things, they tend not to do it until the week before the enforcement date.
    Mike:
    Imagine that. Procrastination? Come on, now.
    James Ferguson:
    And so that's sort of, when our executives are looking at adoption rates or whatnot, it's sort of blunted. The desire to extend those out is blunted because, well, people are just going to wait anyways. But that said, I don't want to sort of ... We are pushing fast. We acknowledge that. We are making people a bit even uncomfortable, I would say. And we acknowledge that, but this is something, again, in the balance of the security posture we feel is important for the overall trust in the Salesforce platform and product.
    Mike:
    I mean, the one thing that I've always learned through all of the work that I've done with various teams at Salesforce is for every time you roll something out, another lock, there's always 10 people there trying to pick it, if they haven't already picked it. And so you both have mentioned that unfortunately it's compressed timelines, but it's timelines because we need to make sure that you're building locks and putting that stuff in place before people just have it to where they can blow through it, you know?
    Jay Hurst:
    Absolutely. The best defense is a good offense, I think is a very adequate app saying in this instance. We want to continue to make sure everybody is at a baseline security level, which is the phase we're in right now. It's this horizon zero of how do we get everybody to the minimum baseline, where we feel very comfortable that your data is going to be protected on the Salesforce platform? And it is painful, and it will be painful for the next couple months as these changes really roll out.
    Once we get there, we start thinking about what's our horizon one and our horizon two look like where we can start to add in the extra controls, give customers more levers to pull for their specific use cases, really focus on the experience around this, because I will also fully admit and not try and gloss over the fact that sometimes the wordings of things in the UX that we provide you to turn them on and turn them off is confusing and it's not as easy as it should be, and we're sacrificing some of that ease of use right now for speed of deployment. But the efforts that we have with the Salesforce Trust platform, which is an expanded group that we now have here that is purely focused on how do we not just get everybody secure, but continue to add more and more security features to make sure that Salesforce is the premier example of how an enterprise SaaS company secures their customers' data.
    So that is the journey we're on, and we're taking our customers with us. And as painful as it is, James and myself and the whole team here, we are looking for active feedback. We're engaging with the community on a day-to-day basis just to try and sand down these rough edges as much as we can until we can get the front door built, locked, and then we can really talk about how do we decorate our house now.
    Mike:
    Yeah. But also you mentioned, well, we're doing it and it's going to be painful. I guess I'm on the flip side of that, thinking, "Boy, if I had other applications and they're not going through this as well, that actually is more of a red flag to me," because then now I'm thinking like, "Well, do they not care as much about making sure all of my data on their platform is as secure as possible?"
    Jay Hurst:
    Absolutely. Like I said, it's a journey, not a destination. What is 100% secure today is not as secure tomorrow. With all of the new attack vectors that come out and these capabilities like Mythos and Fable and all of these really, really smart and frankly scary AI capabilities, we have to double and triple down even harder to make sure that we stay as far ahead of that as we can.
    Mike:
    Right. And as I've been reminded, security isn't always about being scary. Security is about being informed and making the right choices so that you have that protection and that understanding, which is really good.
    James Ferguson:
    It's risk management. It's risk management.
    Mike:
    Yeah, absolutely. James and Jay, I want to thank you guys for coming on and walking us through some of this. I know anytime that we offer anybody in our community, whether it's developers or architects or admins, a change, it's always extra work. But I feel like you're right there in answering the questions and helping through some of the hard parts, because I'll be honest, there's not a day that goes by that I don't learn something in security, at my current job and even when I was a Salesforce admin.
    Jay Hurst:
    Absolutely. And thank you, Mike, for helping amplify the message. One of the challenges I think we have at the product side is making sure our customers understand and get the information. We have our blog posts and our help documentation and we send out emails, but any extra we can do to megaphone this and get people aware is definitely valuable, so thank you for this opportunity.
    Mike:
    You bet.
    James Ferguson:
    And thank to all the admins who are out there who are also helping amplify this and helping support the rest of the community. It's one of the great things about Salesforce from the very beginning. It's the huge community support that exists. We couldn't do it if it was just the six PMs on my team. We need everybody involved.
    Mike:
    Yeah. And I think the part of that you take away is while I'm glad there's so many questions online that we had the idea to do this podcast, because that means there's so many people that are engaged and caring, as opposed to rolling something out and, "Hey, did anybody have any questions," and it's crickets. The reverse of that would also be kind of scary too, is there's questions because people care and because they want to understand. And also I think the one thing that I always had to do as an admin was I had to translate all of that from whatever the document said, or the podcast like this or the blog posts, to my users and to my executives, and it's a lot different once you have to take something in and digest it and then be ready for a Q&A. So there's always more to learn, but thank you guys for coming on. We'll definitely have to have you back on.
    Jay Hurst:
    Sounds great.
    Mike:
    Talk more security.
    James Ferguson:
    Appreciate it. Looking forward to it.
    Mike:
    Big thanks to Jay and James for helping us understand MFA step-up, phishing-resistant authentication, and the role admins play in protecting business systems. Now, of course, we know security is a shared responsibility, and admins are right in the middle of making it real for users, executives and, well, everybody in the organization. So be sure to listen, subscribe and share this episode out, and work through those security changes. You got this. Don't worry. Until next time, we'll see you in the cloud.
  • Salesforce Admins Podcast

    How MuleSoft Helps Salesforce Admins Build Better Agents

    09/07/2026 | 28 mins.
    Today on the Salesforce Admins Podcast, we talk to Mofeyi Oluwalana, Director of Product Management at Salesforce. Join us as we chat about MuleSoft, Flow, Agentforce, and what happens when agents need to take action beyond Salesforce. You should subscribe for the full episode, but here are a few takeaways from our conversation with Mofeyi […]

    The post How MuleSoft Helps Salesforce Admins Build Better Agents appeared first on Salesforce Admins.
More Business podcasts
About Salesforce Admins Podcast
The Salesforce Admins podcast features real-life Salesforce Admins, product managers, and community leaders who transform businesses, careers, and community with clicks, not code. This 20min (sometimes a bit more) weekly podcast hosted by Mike Gerholdt feature episodes to empower Salesforce Admins who are implementing Enterprise CRM solutions. There may be some (digital) confetti. For more than our most recent episodes, go to https://admin.salesforce.com/salesforce-admin-podcast.
Podcast website

Listen to Salesforce Admins Podcast, She's On The Money and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features