An organization requires that all users logging into Snowflake from outside the corporate network must provide a second authentication factor. How can an architect enforce this requirement globally?
Trap 1: Apply a network policy that forces MFA for all IP ranges.
Network policies are designed to restrict access based on IP address ranges or virtual networks. They do not have built-in capabilities to trigger or enforce Multi-Factor Authentication events. MFA settings are managed within the user profile or via external Identity Provider integrations, not through network-level access control rules.
Trap 2: Set the global parameter MFA_ENFORCE to TRUE.
There is no global parameter named MFA_ENFORCE in Snowflake. MFA is enabled on a per-user basis or through integration with an Identity Provider using SCIM or SAML. While you can mandate MFA for individual users, Snowflake does not provide a single toggle switch for global account-wide MFA enforcement.
Trap 3: Configure the CLIENT_SESSION_KEEP_ALIVE parameter.
The CLIENT_SESSION_KEEP_ALIVE parameter controls how long a session remains active after inactivity before the user is required to re-authenticate. It has no functional relationship with Multi-Factor Authentication. Modifying this setting will not trigger an MFA prompt or enforce any additional security layers beyond standard credential-based session management.
- A
Apply a network policy that forces MFA for all IP ranges.
Why it fails: Network policies are designed to restrict access based on IP address ranges or virtual networks. They do not have built-in capabilities to trigger or enforce Multi-Factor Authentication events. MFA settings are managed within the user profile or via external Identity Provider integrations, not through network-level access control rules.
- B
Set the global parameter MFA_ENFORCE to TRUE.
Why it fails: There is no global parameter named MFA_ENFORCE in Snowflake. MFA is enabled on a per-user basis or through integration with an Identity Provider using SCIM or SAML. While you can mandate MFA for individual users, Snowflake does not provide a single toggle switch for global account-wide MFA enforcement.
- C
Use an Authentication Policy to mandate MFA for specific network conditions.
Authentication policies allow administrators to define specific rules for authentication, including the enforcement of MFA. By applying these policies to the account or specific users, architects can require MFA triggers based on network location or other context, providing the granular control necessary for securing enterprise access across diverse user environments.
- D
Configure the CLIENT_SESSION_KEEP_ALIVE parameter.
Why it fails: The CLIENT_SESSION_KEEP_ALIVE parameter controls how long a session remains active after inactivity before the user is required to re-authenticate. It has no functional relationship with Multi-Factor Authentication. Modifying this setting will not trigger an MFA prompt or enforce any additional security layers beyond standard credential-based session management.