Salesforce Enterprise Rbac
jeremylongshore/tons-of-skills-marketplace
Review and govern Salesforce enterprise access across profiles, permission sets and groups, sharing, field access, OAuth apps, SSO, and privileged roles.
Configure Multi-Factor Authentication (MFA) for Salesforce Experience Site users.
$ npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forcedotcom/sf-skills experience-ui-bundle-mfa-configure --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/experience-ui-bundle-mfa-configure .claude/skills/experience-ui-bundle-mfa-configure && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "experience-ui-bundle-mfa-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-ui-bundle-mfa-configure into .claude/skills/experience-ui-bundle-mfa-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "experience-ui-bundle-mfa-configure", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-ui-bundle-mfa-configureType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forcedotcom/sf-skills experience-ui-bundle-mfa-configure --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/experience-ui-bundle-mfa-configure .agents/skills/experience-ui-bundle-mfa-configure && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "experience-ui-bundle-mfa-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-ui-bundle-mfa-configure into .agents/skills/experience-ui-bundle-mfa-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "experience-ui-bundle-mfa-configure", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forcedotcom/sf-skills experience-ui-bundle-mfa-configure --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/experience-ui-bundle-mfa-configure .cursor/skills/experience-ui-bundle-mfa-configure && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "experience-ui-bundle-mfa-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-ui-bundle-mfa-configure into .cursor/skills/experience-ui-bundle-mfa-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "experience-ui-bundle-mfa-configure", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forcedotcom/sf-skills.git --path skills/experience-ui-bundle-mfa-configure--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forcedotcom/sf-skills experience-ui-bundle-mfa-configure --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/experience-ui-bundle-mfa-configure .gemini/skills/experience-ui-bundle-mfa-configure && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "experience-ui-bundle-mfa-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-ui-bundle-mfa-configure into .gemini/skills/experience-ui-bundle-mfa-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "experience-ui-bundle-mfa-configure", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forcedotcom/sf-skills experience-ui-bundle-mfa-configureInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/experience-ui-bundle-mfa-configure .github/skills/experience-ui-bundle-mfa-configure && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "experience-ui-bundle-mfa-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-ui-bundle-mfa-configure into .github/skills/experience-ui-bundle-mfa-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "experience-ui-bundle-mfa-configure", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forcedotcom/sf-skills experience-ui-bundle-mfa-configure --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/experience-ui-bundle-mfa-configure .opencode/skills/experience-ui-bundle-mfa-configure && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "experience-ui-bundle-mfa-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/experience-ui-bundle-mfa-configure into .opencode/skills/experience-ui-bundle-mfa-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "experience-ui-bundle-mfa-configure", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
experience-ui-bundle-mfa-configureConfigure Multi-Factor Authentication (MFA) for Salesforce Experience Site users.
Experience UI Bundle Mfa Configure is an agent skill from forcedotcom/sf-skills. Configure Multi-Factor Authentication (MFA) for Salesforce Experience Site users. TRIGGER when: user wants to enable MFA on a community, enforce two-factor authentication for portal users, add MFA to a React Experience Site / Web App, configure ForceTwoFactor permission, create MFA permission sets for external users, or troubleshoot MFA not appearing on login. Also triggers on: MFA community, two-factor portal, ForceTwoFactor permission set, MFA Experience Cloud, MFA React site, identity verification community…
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files and assets (for example `references/branding.md`, `references/setup.md` and `references/social-login.md`).
It sits in Sales & Support, covering CRM management and Authentication. It works with Salesforce and React. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
sfjqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Experience UI Bundle Mfa Configure loads about 4.8k tokens when it runs, and up to ~8.2k if it reads all its reference files. Until then it costs about 231 tokens; SKILL.md has 1,808 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 1,808 words, ~4,848 tokens.
.claude/skills/experience-ui-bundle-mfa-configure/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Enable Multi-Factor Authentication for Experience Site (Community) users by deploying the correct permission sets and verifying the platform-handled MFA challenge flow.
In scope:
ForceTwoFactor permission set for community usersApiEnabled permission set (required for post-login API calls)Out of scope — delegate elsewhere:
experience-ui-bundle-frontend-generateplatform-permission-set-generatedx-org-permission-set-assignplatform-metadata-deployBefore using this skill, ensure the following are already in place:
| Prerequisite | Why |
|---|---|
| Experience Cloud site deployed and active | MFA applies to community login — no site means no login flow to protect |
| Community users exist (or will self-register) | Permission sets are assigned to community users; the site must have a community-enabled profile |
| Customer Community or Customer Community Login license enabled | Required for community user profiles — without it, user creation and profile deployment will fail |
| Network/Site published at least once | The site must be reachable at its URL for login + MFA challenge to appear |
Note: This skill does NOT handle org setup, license provisioning, or Experience Cloud site creation. If these prerequisites are missing, set them up first via Setup > Digital Experiences > All Sites > New, or deploy your site's base app bundle.
Gather before acting:
| Input | How to determine |
|---|---|
| Target org | Org alias for sf CLI commands |
| Site name | Experience Site (Network) name — resolve via SELECT Id, Name FROM Network (see Step 1); this is the site/Network name, NOT the uiBundles/ app name |
| Community users | Which users or profiles to assign MFA to |
These facts are non-obvious and frequently cause confusion:
| Fact | Detail |
|---|---|
| No custom UI needed | Platform renders the MFA challenge page — no React/LWC component required |
| ForceTwoFactor permission | The ONLY way to enforce MFA for community users at login |
| Org Identity Verification checkbox | Does NOT enforce MFA for community/portal users — only for internal users |
| vforcesite domain | MFA challenge page is always served from the underlying Force.com Site domain — this is expected |
| Always deploy ApiEnabled | React Experience Sites make post-login REST/Connect API calls (sdk.graphql, sdk.fetch); without ApiEnabled they fail with API_DISABLED_FOR_ORG |
| Social Login / SSO is separate from MFA | React sites render configured Auth Providers via the built-in Social Login component (shipped in 264) — driven by Auth Provider setup, not by the MFA permission sets. See references/social-login.md. |
| Login-page branding works for React sites | Since 264, the NetworkBranding "Login & Registration" section is shown in Setup for Site Containers, so logo/color/footer can be customized in the UI — Metadata API still works too. |
These are React Experience Sites, so both permission sets are always deployed —
ForceTwoFactor (enforces MFA) and ApiEnabled (React sites make post-login API
calls).
Resolve the Experience Site's real name and Id from the org — do not assume the
uiBundles/ app folder name is the site name. They are frequently different, and the
site name must come from the org (the deploy target), not the local project.
<site-name> and <NETWORK_ID> below come from here:
sf data query --target-org <org-alias> \
--query "SELECT Id, Name FROM Network" --jsonName as <site-name> and Id as <NETWORK_ID>.First, detect the project's source directory:
jq -r '.packageDirectories[0].path + "/main/default"' sfdx-project.jsonUse the result as <source-dir> (e.g. force-app/main/default) for all commands below.
Write both permission sets (React Experience Sites always need both):
assets/MFA_Required_For_Community.permissionset-meta.xml<source-dir>/permissionsets/MFA_Required_For_Community.permissionset-meta.xml in the user's projectassets/API_Enabled_For_Community.permissionset-meta.xml<source-dir>/permissionsets/API_Enabled_For_Community.permissionset-meta.xmlsf project deploy start \
--source-dir <source-dir>/permissionsets \
--target-org <org-alias> --test-level NoTestRunBefore assigning permission sets to users, verify that the community profile is registered as a site member. Without this, community users cannot log in at all (and MFA will never trigger).
sf data query --target-org <org-alias> \
--query "SELECT Id, ParentId FROM NetworkMemberGroup WHERE NetworkId = '<NETWORK_ID>'" --jsonsf data query --target-org <org-alias> \
--query "SELECT Id, Name FROM Profile WHERE UserType IN ('CspLitePortal', 'PowerCustomerSuccess') AND Name LIKE '%Community%'" --json.network-meta.xml:<networkMemberGroups>
<!-- Replace with the community profile name from Step 3b query above -->
<profile>YOUR_COMMUNITY_PROFILE_NAME</profile>
<!-- existing entries -->
</networkMemberGroups>sf project deploy start \
--source-dir <source-dir>/networks \
--target-org <org-alias> --test-level NoTestRunIMPORTANT: If the community profile is not a member of the network, users with that profile CANNOT log in — meaning MFA will never be triggered even if permission sets are correctly assigned. This is a common misconfiguration in freshly deployed orgs.
The site login page runs as the guest user (unauthenticated). If the guest profile doesn't have access to login Apex classes, users will get FORBIDDEN: You do not have access to the Apex class named: UIBundleLogin and can never reach the MFA challenge.
sf data query --target-org <org-alias> \
--query "SELECT Id, Username, Profile.Name, Profile.Id FROM User WHERE UserType = 'Guest' AND IsActive = true" --jsonUIBundleLogin, UIBundleAuthUtils, UIBundleForgotPassword, UIBundleChangePassword, UIBundleRegistration, and UIBundleSocialLoginConfig. Run the anonymous Apex in references/setup.md ("Grant Guest Profile Apex Class Access") — it diffs existing access and inserts only what's missing — or deploy <classAccess> entries for the same classes to the guest profile metadata XML.IMPORTANT: This is NOT MFA-specific, but without it the login page itself is broken. The skill must validate this to ensure MFA can actually be triggered. Common in freshly deployed orgs where the guest profile didn't get full class access.
Find community users:
sf data query --target-org <org-alias> \
--query "SELECT Id, Username, Name, Profile.Name FROM User WHERE UserType IN ('CspLitePortal', 'PowerCustomerSuccess', 'CustomerSuccess') AND IsActive = true" --jsonFind the permission set IDs:
sf data query --target-org <org-alias> \
--query "SELECT Id, Name FROM PermissionSet WHERE Name IN ('MFA_Required_For_Community', 'API_Enabled_For_Community')" --jsonAssign to each user:
sf data create record --target-org <org-alias> --sobject PermissionSetAssignment \
--values "AssigneeId='<USER_ID>' PermissionSetId='<PERM_SET_ID>'" --jsonAlternatively, delegate to dx-org-permission-set-assign skill:
sf org assign permset --name MFA_Required_For_Community --target-org <org-alias> --json
sf org assign permset --name API_Enabled_For_Community --target-org <org-alias> --jsonAsk the user: "No active community users found in this org. Would you like me to create a test community user so you can verify MFA is working?"
If user agrees, create a test community user:
sf data query --target-org <org-alias> \
--query "SELECT Id, Name FROM Profile WHERE UserType IN ('CspLitePortal', 'PowerCustomerSuccess') AND Name LIKE '%Customer Community%'" --jsonsf data create record --target-org <org-alias> --sobject Account \
--values "Name='MFA Test Account'" --jsonsf data create record --target-org <org-alias> --sobject Contact \
--values "FirstName='MFA' LastName='Test User' Email='mfa.testuser@<site-name>.test' AccountId='<ACCOUNT_ID>'" --jsonsf data create record --target-org <org-alias> --sobject User \
--values "FirstName='MFA' LastName='Test User' Email='mfa.testuser@<site-name>.test' Username='mfa.testuser@<site-name>.test' Alias='mfatest' ProfileId='<PROFILE_ID>' ContactId='<CONTACT_ID>' EmailEncodingKey='UTF-8' LanguageLocaleKey='en_US' LocaleSidKey='en_US' TimeZoneSidKey='America/Los_Angeles'" --jsonsf data update record --target-org <org-alias> --sobject User \
--where "Username='mfa.testuser@<site-name>.test'" \
--values "IsActive=true" --jsonsf org generate password --target-org <org-alias> --on-behalf-of mfa.testuser@<site-name>.test --jsonsf org assign permset --name MFA_Required_For_Community --target-org <org-alias> --on-behalf-of mfa.testuser@<site-name>.test --json
sf org assign permset --name API_Enabled_For_Community --target-org <org-alias> --on-behalf-of mfa.testuser@<site-name>.test --jsonReport the credentials to the user so they can test:
"Created test user:
mfa.testuser@<site-name>.testwith password:<generated-password>. You can use these credentials to verify MFA on your site."
IMPORTANT: Community users require Account → Contact → User hierarchy. Creating a User without a linked Contact on a community profile will fail.
networkMemberGroupsis a membership/access gate — it lists the profiles and permission sets whose holders count as members of the site. It does not assign MFA to users. Assignment happens in Step 4 (per user); register the sets here so assigned users still count as site members.
.network-meta.xml in the project:find . -name "*.network-meta.xml" -not -path "*/node_modules/*"Read the file and locate the <networkMemberGroups> section.
Add the permission set entries (if not already present):
<networkMemberGroups>
<!-- Replace with the community profile name from Step 3b query -->
<profile>YOUR_COMMUNITY_PROFILE_NAME</profile>
<!-- Add MFA and API permission sets -->
<permissionSet>MFA_Required_For_Community</permissionSet>
<permissionSet>API_Enabled_For_Community</permissionSet>
</networkMemberGroups>IMPORTANT: Network metadata deploys are declarative — whatever you deploy becomes the full state. Do NOT create a new
.network-meta.xmlfrom scratch. Always read the existing file and add entries to it.
sf project deploy start \
--source-dir <source-dir>/networks \
--target-org <org-alias> --test-level NoTestRunsf community publish --name "<site-name>" --target-org <org-alias>Verification steps:
| Rule | Rationale |
|---|---|
| Never use the org-wide Identity Verification checkbox for community MFA | It only affects internal users — has no effect on community login |
Always deploy ApiEnabled for React sites | Post-login API calls (sdk.graphql, sdk.fetch) will fail without it |
| Permission set names are exact — do not rename | MFA_Required_For_Community and API_Enabled_For_Community are the canonical names |
| Do not build custom MFA UI components | Platform handles the entire MFA challenge flow — custom UI would duplicate and conflict |
| Always assign before testing | Deployment alone does not activate MFA — assignment to specific users is required |
| Symptom | Cause | Fix |
|---|---|---|
| No MFA challenge on login | ForceTwoFactor permission not assigned to user | Verify PermissionSetAssignment exists for the user |
API_DISABLED_FOR_ORG after login | Missing ApiEnabled permission | Assign API_Enabled_For_Community permission set |
| MFA page shows default Salesforce branding | No NetworkBranding metadata deployed | Read references/branding.md and deploy custom branding |
vforcesite in MFA page URL | Expected behavior — not a bug | Platform serves login/MFA from Force.com Site domain |
| Identity Verification enabled but no community MFA | Wrong mechanism used | Use ForceTwoFactor via Permission Set instead |
| User already has MFA but isn't challenged | Active session exists | Test in incognito/private browser |
| Permission set deployed but MFA not enforced | Deployed but not assigned | Run assignment step — deploy != assign |
| No community users found in org | Users haven't been created or self-registered yet | Offer to create a test community user (Account → Contact → User hierarchy) for verification. Permission sets are still deployed and networkMemberGroups updated — org is MFA-ready for when users exist. |
| New users aren't automatically protected by MFA | networkMemberGroups only defines site membership — it does not assign permission sets to users | Assign MFA_Required_For_Community + API_Enabled_For_Community to each user that needs it (Step 4) |
FORBIDDEN: You do not have access to the Apex class named: UIBundleLogin | Site guest profile missing Apex class access | Run Step 3c to grant guest profile access to all UIBundle login classes |
Community user can't log in (redirects silently or gets portal user email settings error) | Community profile not a network member, or email deliverability not set to All Email | Add profile to .network-meta.xml <networkMemberGroups> and redeploy (Step 3b). Verify email deliverability is set to "All Email" in Setup → Email → Deliverability. |
Files generated in the user's project:
| File | When |
|---|---|
permissionsets/MFA_Required_For_Community.permissionset-meta.xml | Always |
permissionsets/API_Enabled_For_Community.permissionset-meta.xml | Always |
When summarizing what was done, do NOT claim that adding permission sets to
<networkMemberGroups>(or updating the network) causes new or self-registered users to automatically get MFA. It does not —networkMemberGroupsonly defines site membership. MFA is enforced only for users the permission set has been explicitly assigned to (Step 4). Report network changes as "registered the permission sets as site members," not as auto-assignment.
| When | Delegate to |
|---|---|
| User only needs to assign (already deployed) | dx-org-permission-set-assign |
| User needs to deploy all project metadata | platform-metadata-deploy |
| User wants to customize the login page UI | experience-ui-bundle-frontend-generate |
| User needs to create a new generic permission set | platform-permission-set-generate |
| User wants IDP/Social Login (different from MFA) | Supported on React sites — the built-in Social Login component renders linked Auth Providers on the login page automatically. Create the Auth Providers in Setup, then link them to the React site via the experience-ui-bundle-deploy social login step (socialLogin in org-setup.config.json) — the React SSO admin UI is hidden, so linking is programmatic, not a Setup click-path. See references/social-login.md. |
| File | When to read |
|---|---|
assets/MFA_Required_For_Community.permissionset-meta.xml | Step 2 — writing permission set to project |
assets/API_Enabled_For_Community.permissionset-meta.xml | Step 2 — always deployed |
references/branding.md | When user wants to customize MFA/login page appearance |
references/social-login.md | When user wants IDP/SSO/Social Login on a React site alongside or instead of MFA |
references/setup.md | Steps 3–5 — detailed assignment, network membership, and publish reference |
© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references, assets) in skills/experience-ui-bundle-mfa-configure of forcedotcom/sf-skills.
Open the folder on GitHubat commit e5164d9
Experience UI Bundle Mfa Configure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Experience UI Bundle Mfa Configure this skillforcedotcom/sf-skills | 1.1k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| Salesforce Enterprise Rbacjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Gh Bot Commentjetstreamapp/jetstream | 125 | — | ~616 | Automated safety check: Pass | Custom licence | |
| Sf ApexJaganpro/sf-skills | 424 | — | ~2k | Automated safety check: Pass | MIT | |
| Sf DebugJaganpro/sf-skills | 424 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Churn Riskindranilbanerjee/digital-marketing-pro | 855 | 1 repos | ~2.4k | Automated safety check: Pass | MIT |
jeremylongshore/tons-of-skills-marketplace
Review and govern Salesforce enterprise access across profiles, permission sets and groups, sharing, field access, OAuth apps, SSO, and privileged roles.
jetstreamapp/jetstream
Post GitHub PR/issue comments, reviews, and review replies as the Jetstream bot account instead of the user's personal account.
Jaganpro/sf-skills
Generates and reviews Salesforce Apex code with 150-point scoring.
Jaganpro/sf-skills
Salesforce debug log analysis and troubleshooting with 100-point scoring.
indranilbanerjee/digital-marketing-pro
Score customer segments for churn risk from behavioral signals — email engagement decline, purchase recency, usage drops, support sentiment — producing a 0-100 risk scorecard with four tiers…
indranilbanerjee/digital-marketing-pro
Import leads into Salesforce, HubSpot, Zoho, or Pipedrive with validation, deduplication against existing CRM records, lead scoring, consent and compliance checks, and source attribution — then push…
forcedotcom/sf-skills
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.
forcedotcom/sf-skills
Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.
forcedotcom/sf-skills
Lightning Web Components with PICKLES methodology and 165-point scoring.
Works with
Categories
Configure Multi-Factor Authentication (MFA) for Salesforce Experience Site users. Experience UI Bundle Mfa Configure is an agent skill from forcedotcom/sf-skills. Configure Multi-Factor Authentication (MFA) for Salesforce Experience Site users.
Experience UI Bundle Mfa Configure fits situations like: : user wants to enable MFA on a community; enforce two-factor authentication for portal users; add MFA to a React Experience Site / Web App; configure ForceTwoFactor permission.
Run `npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a claude-code`. Or copy the skill folder (skills/experience-ui-bundle-mfa-configure in forcedotcom/sf-skills) into .claude/skills/experience-ui-bundle-mfa-configure in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a codex`. Or copy the skill folder (skills/experience-ui-bundle-mfa-configure in forcedotcom/sf-skills) into .agents/skills/experience-ui-bundle-mfa-configure in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill experience-ui-bundle-mfa-configure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/experience-ui-bundle-mfa-configure, .gemini/skills/experience-ui-bundle-mfa-configure, .github/skills/experience-ui-bundle-mfa-configure and .opencode/skills/experience-ui-bundle-mfa-configure in your project.
Going by SKILL.md and its folder, Experience UI Bundle Mfa Configure needs the command-line tools its instructions call (sf and jq).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Experience UI Bundle Mfa Configure is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Experience UI Bundle Mfa Configure: Salesforce Enterprise Rbac (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Gh Bot Comment (jetstreamapp/jetstream, 125 stars), Sf Apex (Jaganpro/sf-skills, 424 stars) and Sf Debug (Jaganpro/sf-skills, 424 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.
Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.