Loading
Upcoming Mandatory Changes to Public Key Infrastructure (PKI)Read More
Agentforce Web Agent IssuesRead More
Salesforce Enforces New Security Requirements in Summer 2026Read More
Secure Your Salesforce Org
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Manage Session Policies for a Connected App: Connected App High Assurance Required Control

          Manage Session Policies for a Connected App: Connected App High Assurance Required Control

          This security setting mandates that users accessing a specific connected application must possess a session security level categorized as high assurance.

          Control Name

          Connected Apps: Manage Session Policies for a Connected App: Connected App High Assurance Required

          Recommended Configuration

          High assurance session required - Selected "Block this application | Raise the session level to high assurance".

          Control Overview

          This security setting mandates that users accessing a specific connected application must possess a session security level categorized as high assurance, typically achieved through multi-factor authentication.

          Security Risk If Not Configured

          Missing high assurance session requirements for connected apps lead to a vulnerability where attackers perform sensitive actions or access-protected data without a secondary authentication factor.

          Threat Scenarios

          An attacker who has compromised a user's primary password gains full access to a connected app integration and its data because the application does not trigger a supplemental identity challenge to verify the session.

          Estimated CVSS Score Range

          High (7.0–8.9).

          Risk Impact Considerations

          Failure to enforce high assurance levels facilitates unauthorized lateral movement and data exfiltration from integrated systems that rely on the Salesforce session as the primary trust anchor.

          Higher Risk When

          When the connected application is granted administrative scopes or is able to modify critical org metadata and security configurations.

          Low Risk When

          If the company already enforces universal multi-factor authentication at the global login level or uses certificate-based authentication for all user sessions.

          Business and Integration Considerations

          High assurance is the secure standard for applications handling sensitive data, while standard security levels may be appropriate for low-risk read-only tools to minimize user friction during non-critical tasks.

          Recommended Remediation

          Go to Manage Connected Apps, select the specific application, and under Session Policies, select the checkbox for High assurance session required.

          Security Health Review Guidance

          Security Health Review identifies high assurance enforcement as a strongly recommended standard for all integrations processing sensitive data to make sure that a single credential compromise cannot lead to a full system breach.

           
          Loading
          Salesforce Help | Article