Skip to content
Back to skills

Session High Assurance Policies

ASecurity

Enforce step-up authentication for sensitive pages/objects using High Assurance session level and login flow policies. NOT for initial MFA enrollment UX.

  • 15 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added June 1, 2026
ai-agentsrustgospringapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 7 files and shows the line behind each finding

Scanned June 1, 2026

npx -y skills add PranavNagrecha/AwesomeSalesforceSkills --skill session-high-assurance-policies --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Session High Assurance Policies?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Session High Assurance Policies
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/pranavnagrecha-session-high-assurance-policies/badge)](https://www.skillsdirectory.com/skills/pranavnagrecha-session-high-assurance-policies)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: session-high-assurance-policies
description: "Enforce step-up authentication for sensitive pages/objects using High Assurance session level and login flow policies. NOT for initial MFA enrollment UX."
category: security
salesforce-version: "Spring '25+"
well-architected-pillars:
  - Security
triggers:
  - "step up auth for sensitive record"
  - "high assurance session salesforce"
  - "require mfa to view ssn field"
  - "session level policy"
tags:
  - session
  - mfa
  - high-assurance
inputs:
  - "Which objects/pages require step-up"
  - "current login policies"
outputs:
  - "Session Settings policy"
  - "profile/permission-set config"
dependencies: []
version: 1.0.0
author: Pranav Nagrecha
updated: 2026-04-28
---

# Session High Assurance Policies

Salesforce sessions have a Security Level: Standard or High Assurance. A High Assurance Session Policy forces re-authentication with MFA when a user accesses a flagged object, report, or page. This skill configures the policy and tests it against the sensitive records.

## Recommended Workflow

1. Identify the 1-3 objects/pages that justify High Assurance (scope carefully).
2. Setup → Session Settings → Policies: set the session level for the profile or permission set to 'High Assurance'.
3. For records: use a Login Flow or an Apex service that checks UserInfo.getSessionSecurityLevel() and redirects to MFA if Standard.
4. Write a test: log in from a non-MFA device, navigate to the record, confirm the step-up prompt.
5. Document the UX impact and communicate to the affected user population.

## Key Considerations

- Session security level is per session, not per action; once stepped up the user stays High Assurance until logout.
- Connected apps can be configured with High Assurance requirements separately.
- Mobile SDK apps must support the Refresh Token flow with device PIN to honor High Assurance.
- High Assurance ≠ MFA; it means the session was created with a secondary factor.

## Worked Examples (see `references/examples.md`)

- *Require HA to view SSN field* — HR org.
- *Connected app HA requirement* — Mobile app used by auditors.

## Common Gotchas (see `references/gotchas.md`)

- **Org-wide HA breaks integrations** — API-only integration users fail login.
- **Step-up on report** — Users hit the prompt on every refresh.
- **Mobile SDK crash** — App fails to refresh.

## Top LLM Anti-Patterns (full list in `references/llm-anti-patterns.md`)

- Applying HA org-wide
- Forgetting integration user profiles
- Using HA as a substitute for field-level security

## Official Sources Used

- Apex Developer Guide — Sharing — https://developer.salesforce.com/docs/atlas.en-us.apexcode.meta/apexcode/apex_bulk_sharing_understanding.htm
- Salesforce Security Guide — https://help.salesforce.com/s/articleView?id=sf.security.htm
- Shield Platform Encryption — https://help.salesforce.com/s/articleView?id=sf.security_pe_overview.htm
- Session Security Levels — https://help.salesforce.com/s/articleView?id=sf.security_hap_session.htm
- CSP and Trusted URLs — https://help.salesforce.com/s/articleView?id=sf.security_csp_overview.htm
- API Only User Profile — https://help.salesforce.com/s/articleView?id=sf.users_profiles_api_only.htm
- Privacy Center and DSR — https://help.salesforce.com/s/articleView?id=sf.privacy_center_overview.htm

Files in this skill

  • SKILL.md3.3 KB
  • references/examples.md734 B
  • references/gotchas.md740 B
  • references/llm-anti-patterns.md246 B
  • references/well-architected.md923 B
  • scripts/check_session_high_assurance_policies.py956 B
  • templates/session-high-assurance-policies-template.md564 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…