Login Access is a native functionality of the Salesforce platform that allows a user to log in to an organization as another user via UI, API, or mobile for testing and troubleshooting purposes.
For more information about this feature, see our Grant Login Access documentation.
Salesforce Support users may request Login Access when it is necessary to log in to Salesforce applications to replicate, isolate, troubleshoot, and ultimately resolve issues stemming from customer initiated support inquiries when support is not possible with existing access to a customer's organization settings, setup tree, or other customer metadata.
No one within Salesforce Support may log in to your organization to resolve issues without this explicit permission and duration for the access.
In order for Salesforce Support users to use Login Access to log in to a customer's organization, the customer themselves (i.e. the individual user) must first use the process outlined in “grant login Support with login access to your organization” to explicitly approve Salesforce Support's request to log in with their user profile.
Salesforce Support users then follow an explicit internal process to document that their use of Login Access is permitted in a Support case.
The ability for Salesforce Support users to use Login Access to log in to customer organizations itself goes through an approval process for each individual employee or partner who requests this access to do their necessary job functions. Only a small subset of full-time employees and trusted, contractually-bound partners (less than 6% of all active employees/partners) have the ability to use Login Access to log in to customer organizations.
When using Login Access, Salesforce Support users have the same record and data access and application and administrative rights as the user they are logged in as.
For example: If the Support user is logged in as a limited-access end user then the Support user will only have that level of access in the customer organization. Alternatively, if the Support user is logged in via an administrator user or another user with elevated access, that is what the Support user sees.
Support users will request that any UI actions (clicks) that result in changes to a production environment be performed by the customer.
Support users may make changes to lower environments (e.g. sandboxes), but the Support user must first obtain written approval from the customer (via case comments) for any requested changes and the changes are approved in accordance with our internal process (Please Note: Data 360 and Agentforce Support will not make any changes in any environment via login access).
Support users cannot export data from a customer’s organization via the UI.
There are safeguards built into the Salesforce Platform which prevent unauthorized changes to a customer organization's security posture while using Login Access.
For example:
In addition to these Platform security features, the access granted to Salesforce Support when using Login Access is restricted to the user they are logged in as, so they can only see and do what the user they are logged in as can see and do.
When granting Login Access to Salesforce Support, the customer user themselves explicitly selects a duration for which Login Access for Salesforce Support will remain active for their user account.
This access is typically granted for any of the following periods of time:
The customer user can update the duration of, or revoke, Login Access granted at any time. No one other than the individual customer user can change or revoke Login Access on behalf of that user.
Instead of using the Login Access feature, Salesforce Support users who support customers with the “Admin Assist” entitlement use the Premier Courtesy Licenses which were provisioned as a part of that entitlement in order to log in to customer organizations.
The list of tasks that Admin Assist are allowed to perform on a customer's behalf are outlined in Admin Assist: Task List.
000388857

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.