nerdexam
Salesforce

ADM-201 · Question #187

When users log In to Salesforce via the user interface, which two settings does the system check for authentication? Choose 2 answers

The correct answer is A. The user's TWo-Factor Authentication for API Logins permission D. The user's profile login hours restrictions. When users log in to Salesforce via the user interface, the system authenticates them by checking their assigned profile login hours and specific two-factor authentication permissions, which can include those typically associated with API access for certain client types.

Submitted by jian89· Apr 18, 2026Configuration and Setup

Question

When users log In to Salesforce via the user interface, which two settings does the system check for authentication? Choose 2 answers

Options

  • AThe user's TWo-Factor Authentication for API Logins permission
  • BThe role IP address restrictions
  • CThe users TWo-Factor Authentication for User Interface Logins permission
  • DThe user's profile login hours restrictions

How the community answered

(32 responses)
  • A
    91% (29)
  • B
    3% (1)
  • C
    6% (2)

Why each option

When users log in to Salesforce via the user interface, the system authenticates them by checking their assigned profile login hours and specific two-factor authentication permissions, which can include those typically associated with API access for certain client types.

AThe user's TWo-Factor Authentication for API Logins permissionCorrect

The "Two-Factor Authentication for API Logins" permission ensures MFA for programmatic access, and is also relevant for UI logins through client applications like mobile apps that interact with Salesforce via APIs, thus serving as an authentication check.

BThe role IP address restrictions

IP address restrictions are typically configured at the profile level, not the role level, to control the network locations from which users can log in.

CThe users TWo-Factor Authentication for User Interface Logins permission

While the "Two-Factor Authentication for User Interface Logins" permission directly governs browser-based UI MFA, the "API Logins" permission can cover UI logins for client applications using APIs, making the API permission the broader or intended choice in this context.

DThe user's profile login hours restrictionsCorrect

The user's profile login hours restrict the specific times during which they are permitted to log in to Salesforce via the user interface, blocking access outside these defined windows as a key authentication barrier.

Concept tested: User login authentication checks

Source: https://help.salesforce.com/s/articleView?id=sf.admin_loginaccess.htm&type=5

Topics

#User Authentication#Profile Settings#Login Restrictions#Multi-Factor Authentication (MFA)

Community Discussion

No community discussion yet for this question.

Full ADM-201 Practice