Why are our Salesforce accounts getting blocked for high-risk proxies?
Legitimate network connections are being incorrectly flagged as high-risk anonymizing proxies like TOR or Mullvad, causing administrator accounts to be repeatedly blocked. This leaves organizations locked out of their accounts for months without a clear way to prevent the behavior.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1Using PowerShell or the Microsoft Graph Explorer to manually update the user's onPremisesSyncBehavior property by setting isCloudManaged to true.
In their words
Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.
“It has been two months, and all of our Salesforce accounts have started getting blocked.”source ↗
“We are not using any public VPNs or public proxies, but the accounts continue to be blocked due to high-risk anonymizing proxies (e.g., TOR, Mullvad VPN, etc.).”source ↗
“Is there any solution to prevent this behavior and avoid having our accounts blocked?”source ↗
“The owner of the company at one of our MSP customers just had something unexplainable happen. This may shock you but Microsoft is involved. She forgot her email pass to log into a brand new mobile device. I went to change her password and it threw the error "This user's password can't be reset because password writeback isn't turned on for your organization."”source ↗
“This exact thing happened to my coworker at our company 2 weeks ago”source ↗
Where this came up
People with this problem also raised
- 5Antivirus blocking legitimate software updates and installers
- 7Why do smoke detectors go off randomly in the middle of the night?
- 7Account deactivated for security reasons and stuck in ID verification loop
- 2What to do after your bank account is hacked
- 6Why is security software generating so many false alerts?
- 2Why does Etsy keep incorrectly flagging my items as prohibited?