問題文
An account uses SAML single sign-on for all human users. The security team must guarantee that a second factor is presented on every human sign-in, including the sign-ins that go through the identity provider. What must be configured in Snowflake?
選択肢
- A session policy with a short idle timeout, so that users must re-present their factor frequently, which sends each re-authentication back through the identity provider and picks up its factor settings.
- Enrollment of every human user in Snowflake-managed multi-factor authentication.
- Nothing in Snowflake, because the identity provider owns the authentication step and therefore enforces whatever factors the organization has configured on its side before the assertion ever reaches Snowflake.
- An authentication policy whose MFA policy enforces multi-factor authentication on external authentication.