Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response What happens when Salesforce users are allowed to…
Threats, Abuse & Incident Response

What happens when Salesforce users are allowed to log in from untrusted networks without additional checks?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Threats, Abuse & Incident Response

Allowing logins from untrusted networks raises the chance that stolen credentials, phishing attempts, or intercepted sessions will succeed. Attackers do not need physical access if they can authenticate from anywhere. Trusted IP ranges, MFA, and secure remote connectivity add friction for attackers and give security teams a better chance to block suspicious access before data is exposed.

Why Untrusted-Network Logins Raise the Blast Radius

When a Salesforce login is permitted from an untrusted network without any additional check, the organisation is relying almost entirely on the username, password, and session controls already in place. That is a weak position if credentials have been phished, reused, or intercepted, because the attacker can attempt access from any location and blend into normal remote activity.

The practical consequence is not just more login noise. It is faster movement from credential theft to data access, record export, workflow abuse, and account takeover. For SaaS applications, the network path itself is often one of the few signals that can still separate routine access from suspicious access.

Trusted IP ranges, device or context checks, and MFA raise the cost of abuse because they force the attacker to defeat more than one control before the session is accepted. That matters most when the application is exposed to a broad remote workforce, third-party users, or contractors who may authenticate from many different locations.

What Changes When You Remove the Network Check

The main change is that access decisions become less discriminating. If a stolen password is still enough to authenticate from an arbitrary network, the defender loses one of the simplest ways to flag impossible travel, unfamiliar source addresses, or logins that do not fit the normal user pattern.

That also reduces the value of incident response. A security team can still investigate the login, but it has fewer built-in gates to stop the session before the attacker reaches sensitive objects. In practice, this can turn a single compromised credential into a broader compromise of leads, customer records, support cases, or administrative functions.

The strongest internal warning signs are repeated successful logins from unfamiliar geographies, logins that bypass established corporate access paths, and sessions that quickly pivot into data extraction or privilege-sensitive actions. Those patterns deserve review even when the credential itself appears valid.

Risk and Threat Considerations

Permitting untrusted-network access without additional checks materially increases exposure to credential stuffing, phishing, session hijacking, and reuse of credentials stolen elsewhere. It also weakens the organisation’s ability to distinguish legitimate remote work from attacker activity, especially when the attacker is using a valid account rather than forcing entry.

Failure mechanism: The control failure is not that Salesforce becomes openly reachable, but that a valid login from an unexpected network is treated as low risk even when the credential or session may already be compromised.

Impact: Attackers can authenticate remotely, search for valuable records, export data, modify workflows, or escalate through linked applications before defenders have a strong enough signal to stop the session.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementUntrusted-network logins heighten the value of stolen credentials and session abuse.
NHI-03 — Access and Privilege GovernanceTrusted-network checks help constrain where valid credentials can be used.
NHI-08 — Third-Party and Integration RiskRemote SaaS access often involves external users and connected services that expand exposure.
Recommendation — Tighten credential and session controls to reduce the chance that stolen access works remotely. Constrain sensitive access with contextual login checks and least privilege. Review third-party and remote-access paths that can bypass normal trust boundaries.
NIST CSF 2.0PR.AC — Access ControlNetwork-based access restrictions and MFA directly support access control decisions.
DE.CM — Continuous MonitoringSuspicious login locations and patterns need monitoring to detect abuse quickly.
Recommendation — Enforce contextual access restrictions and multi-factor authentication for remote logins. Monitor login source, device, and travel anomalies for suspicious access.
CIS Controls v86 — Access Control ManagementRemote login restrictions and MFA are core access-control safeguards for SaaS access.
Recommendation — Restrict remote access paths and require stronger authentication for sensitive accounts.
NIST SP 800-63IAL/AAL — Identity Assurance and Authenticator AssuranceAdditional checks on unfamiliar networks align with stronger authenticator assurance.
Recommendation — Raise authenticator assurance for users who can access sensitive Salesforce data.

Practitioner Guidance

What to verify: Confirm that trusted network policy is paired with MFA and that exceptions are limited, approved, and reviewable. A network allowlist by itself is not a substitute for phishing-resistant authentication when the threat is stolen credentials.

Decision rule: If users routinely access Salesforce from many networks, treat context-based controls as part of the login policy, not as an optional hardening layer. If a user or role can touch high-value data, require a stronger step-up condition before granting session continuity.

What good looks like: The normal login path should be narrow enough that an unusual source network, unfamiliar device, or impossible travel event creates a meaningful checkpoint rather than a passive log entry.

Practitioner takeaway: The real objective is to make remote access harder to abuse than to obtain, because once a valid SaaS session is established from an untrusted network, the attacker is already past the easiest point of defence.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org