CertSafari
    Snowflake SnowPro Advanced: Security Engineer (SEA-C01)· Lessons

    Domain 1 · Lesson 2/21

    Snowflake MFA, Passkeys, SAML SSO and OAuth Sign-In

    Configure and monitor user authentication and session management.

    11 min read
    5.5% of exam
    5 sources
    Published 5 Oct 2026
    Docs as of 4 Oct 2026

    What you will be able to do

    • Decide which users must enroll in Snowflake MFA and restrict the allowed MFA methods with an authentication policy
    • Require Snowflake MFA on top of IdP authentication for SSO users
    • Recover a locked-out user and set up break-glass access with one-time passcodes
    • Configure a SAML2 security integration, including SP-initiated login, signing, encryption and NameID format
    • Trace the External OAuth flow and diagnose failed SAML sign-ins

    Key concept

    Authentication policy — An authentication policy is a Snowflake policy object that you set on the account or on a user. It decides how that principal may sign in: which authentication methods and security integrations are allowed, whether MFA enrollment is required, and which MFA methods are accepted.

    1.Snowflake-managed MFA: who enrolls, and with which authenticator

    Snowflake-managed MFA protects one kind of sign-in: a human user who signs in with a password. After entering the password, an enrolled user must also present a second factor. Service users can't use MFA. They need another way to authenticate, such as the key pairs and tokens covered in the programmatic-access lesson.

    Whether enrollment is required depends on when the account was created. An account that existed before the 2024_08 behavior change bundle was enabled must be configured to require MFA. An account created after that bundle requires MFA by default for every human user who signs in with a password. In those newer accounts, you can relax the requirement by setting an authentication policy with MFA_ENROLLMENT=OPTIONAL on the account. Even then, Snowsight password users still need MFA, and Snowflake describes this opt-out as temporary because single-factor password sign-ins are being deprecated.

    MFA methods Snowflake accepts as a second factor
    MethodWhat it isDesign note from the docs
    Passkey (PASSKEY)A passkey that can be stored and accessed in a variety of ways, such as on a YubiKeyRecommended for its security and usability
    Authenticator app (TOTP)An app that generates a time-based one-time passcodeAllowed by default
    DuoAuthenticating with DuoUnlike the other methods, Duo is not replicated

    Administrators choose which of these methods are allowed with the MFA_POLICY clause of an authentication policy. The policy below requires enrollment and accepts passkeys and authenticator apps, but not Duo:

    Requiring MFA and allowing only passkeys and TOTPsql
    CREATE AUTHENTICATION POLICY mfa_policy
      MFA_ENROLLMENT = REQUIRED
      MFA_POLICY = (ALLOWED_METHODS = ('PASSKEY', 'TOTP'));

    Checkpoint 1 of 8· Check yourself

    You apply the policy above. A user who enrolled only Duo earlier then signs in. What happens?

    Checkpoint 2 of 8· Exam question

    A security researcher publishes a breach dump, and Snowflake's leaked password protection matches the current password of a PERSON user in your account. What does Snowflake do on its own?

    Sources1

    2.Externally-managed MFA for SSO users

    Externally-managed MFA means that the IdP enforces the second factor, not Snowflake. This is the default for SAML and OIDC users. If you don't trust that boundary for high-privilege users, an authentication policy can add Snowflake MFA after IdP sign-in. The policy lists the allowed methods and the security integrations they may use. It requires enrollment, and the MFA_POLICY clause sets ENFORCE_MFA_ON_EXTERNAL_AUTHENTICATION. The example below is named for its typical use, administrators who must pass both factors.

    Checkpoint 3 of 8· Fill the gap

    Which MFA_POLICY setting makes SSO users complete Snowflake MFA after the IdP sign-in?

    CREATE AUTHENTICATION POLICY ACCOUNTADMIN_DOUBLE_MFA
      AUTHENTICATION_METHODS = ('PASSWORD', 'SAML', 'OIDC')
      SECURITY_INTEGRATIONS = ('<SAML OR OIDC SECURITY INTEGRATIONS>')
      MFA_ENROLLMENT = 'REQUIRED'
      MFA_POLICY=( ? ='ALL');

    Sources1

    3.Recovering locked-out users and break-glass access

    Lockouts happen when a user loses the device that holds their second factor. Administrators have two ways to recover the user. To have the user enroll a new factor, run ALTER USER joe ENROLL MFA;. If the user has a verified email, Snowflake emails them a prompt. If not, Snowflake returns a URL that the administrator passes on. To allow a single-factor password sign-in for a limited window, run ALTER USER joe SET MINS_TO_BYPASS_MFA = 30;. Before re-enrolling, list the user's factors with SHOW MFA METHODS FOR USER joe, then drop the one that is gone with ALTER USER … REMOVE MFA METHOD.

    Break glass covers a different failure: the usual sign-in path is unavailable, for example because the IdP is down. Snowflake's pattern is a dedicated user whose password is kept in a key vault together with pre-generated one-time passcodes (OTPs). Signing in with the password plus an OTP still meets the MFA requirement. Each OTP works only once. Generating a new batch invalidates every earlier passcode, which is also how you revoke them all at once.

    Generating five break-glass one-time passcodessql
    ALTER USER breakglass_user ADD MFA METHOD OTP COUNT = 5;

    Checkpoint 4 of 8· Match them up

    Match each statement to what it does

    Tap a term, then the definition that fits it.

    Sources1

    4.Configuring SAML2 single sign-on

    SSO moves the first factor to your IdP. Snowflake represents the trust relationship as a SAML2 security integration, which replaces the deprecated SAML_IDENTITY_PROVIDER account parameter. The recommended way to describe the IdP is METADATA_URL. With it, Snowflake fetches the IdP's settings, including its certificate, dynamically, so you don't have to paste them in by hand.

    On the service-provider side, the two Snowflake URLs must exactly match the account URL you registered at the IdP. If you omit them, they default to the account's legacy URL. Snowflake appends /fed/login to the ACS URL. The example uses a private-connectivity account URL:

    A SAML2 security integration driven by the IdP's metadata URLsql
    CREATE SECURITY INTEGRATION my_idp
      TYPE = saml2
      ENABLED = true
      METADATA_URL = 'https://integrator-26580.okta.com/app/ex2kbcS30N697/sso/saml/metadata'
      SAML2_SNOWFLAKE_ISSUER_URL = 'https://<orgname>-<account_name>.privatelink.snowflakecomputing.com'
      SAML2_SNOWFLAKE_ACS_URL = 'https://<orgname>-<account_name>.privatelink.snowflakecomputing.com/fed/login';
    SAML2 integration properties you set after creation
    PropertyEffect
    SAML2_ENABLE_SP_INITIATEDEnables Snowflake-initiated SSO (IdP-initiated SSO needs no Snowflake configuration)
    SAML2_SP_INITIATED_LOGIN_PAGE_LABELText that identifies the IdP on the Snowflake login page
    SAML2_SNOWFLAKE_X509_CERTSnowflake's public certificate; the IdP uses it to encrypt assertions and verify signed requests
    SAML2_SIGN_REQUESTSigns SAML requests so the IdP can verify they come from Snowflake
    SAML2_REQUESTED_NAMEID_FORMATThe NameID format requested from the IdP; defaults to emailAddress

    Snowflake decrypts encrypted assertions with its own private key and never exports that key. By default, the certificate is self-signed. If you need a CA-issued certificate, generate a CSR with SYSTEM$GENERATE_SAML_CSR and upload the issued certificate into SAML2_SNOWFLAKE_X509_CERT.

    Checkpoint 5 of 8· Check yourself

    Users should be able to start SSO from a button on the Snowflake login page. What do you configure?

    Checkpoint 6 of 8· Exam question

    Your SOC wants evidence that Snowflake's malicious IP protection is blocking sign-in attempts from anonymizing infrastructure. You also want to relax blocking for one low-risk category used by contractors. Which statements are accurate? (Select all that apply.)(Select 3)

    Sources2

    5.External OAuth, and troubleshooting failed SSO

    OAuth is the other IdP-driven path, used mostly by applications that act for a user. Snowflake supports both Snowflake OAuth and External OAuth. The sources for this lesson cover only the External OAuth flow, so the configuration parameters of Snowflake OAuth integrations are not described here. External OAuth does not depend on where the authorization server runs, whether in any cloud or on-premises. You set up trust once with a security integration. After that, every access attempt follows a fixed sequence.

    Checkpoint 7 of 8· Put it in order

    Put the External OAuth flow in order

    1. 1.The authorization server sends a JSON Web Token to the client application
    2. 2.Snowflake validates the token
    3. 3.Configure the authorization server and a Snowflake security integration to establish trust
    4. 4.The Snowflake driver passes a connection string containing the OAuth token
    5. 5.Snowflake performs a user lookup and starts a session
    6. 6.The user's BI application attempts to verify the user

    A failed SAML sign-in gives the user a UUID. Pass the UUID to SYSTEM$GET_LOGIN_FAILURE_DETAILS to get the error code, then look the code up:

    Extracting the error code for a failed SSO sign-insql
    SELECT JSON_EXTRACT_PATH_TEXT(SYSTEM$GET_LOGIN_FAILURE_DETAILS('eb55b777-50a4-4db5-b231-9ee457fb3981'), 'errorCode');
    Common SAML error codes
    CodeErrorMeaning
    390133SAML_RESPONSE_INVALIDResponse invalid, most likely malformed
    390165SAML_RESPONSE_INVALID_SIGNATUREThe response contains an invalid Signature
    390168SAML_RESPONSE_INVALID_DESTINATIONDestination does not match a valid URL on the account
    390169SAML_RESPONSE_INVALID_AUDIENCENot exactly one audience, or the audience URL is unexpected

    Destination and audience errors usually mean the issuer or ACS URLs don't match what the IdP was given. Signature errors usually follow an IdP certificate change. If the integration uses METADATA_URL, ALTER SECURITY INTEGRATION … REFRESH METADATA_URL re-reads the IdP's settings without changing any other parameter.

    Checkpoint 8 of 8· Check yourself

    After the IdP replaces its signing certificate, SAML sign-ins fail with error 390165. The integration was built with METADATA_URL. What is the least disruptive fix?

    Sources345

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.Requiring MFA_ENROLLMENT also forces SSO users through Snowflake MFA.Why is that wrong?

      By default, Snowflake leaves MFA for SSO users to the IdP. Snowflake MFA after IdP sign-in only applies when an authentication policy sets ENFORCE_MFA_ON_EXTERNAL_AUTHENTICATION.

      Covered in Externally-managed MFA for SSO users

    2. 2.SAML2_SNOWFLAKE_ACS_URL is just the plain account URL.Why is that wrong?

      The ACS URL is the account URL with /fed/login appended, and it must match the URL configured at the IdP.

      Covered in Configuring SAML2 single sign-on

    3. 3.Rotating the IdP certificate means rebuilding the SAML2 integration.Why is that wrong?

      When the integration uses METADATA_URL, a REFRESH METADATA_URL re-reads the IdP's settings, including its certificate, without changing any parameters.

      Covered in External OAuth, and troubleshooting failed SSO

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “MFA is intended for human users who authenticate with a password. Service users must use another form of authentication.”
      ↩︎ Snowflake-managed MFA: who enrolls, and with which authenticator
      “Passkeys are recommended due to their security and usability.”
      ↩︎ Snowflake-managed MFA: who enrolls, and with which authenticator
      “Password users who use Snowsight must still use MFA, but MFA isn’t required for other interfaces.”
      ↩︎ Snowflake-managed MFA: who enrolls, and with which authenticator
      “Snowflake relies on the identity provider (IdP) to enforce MFA or some other strong authentication method.”
      ↩︎ Externally-managed MFA for SSO users
      “After an OTP is used to authenticate, it is invalidated and can’t be used to authenticate again.”
      ↩︎ Recovering locked-out users and break-glass access
      “Previously generated OTPs are invalidated.”
      ↩︎ Recovering locked-out users and break-glass access
      “you can use an authentication policy to control which MFA methods can be used as a second factor of authentication.”
      ↩︎ Key concept
      “By default, Snowflake doesn’t require MFA for users who authenticate with single sign-on (SSO).”
      ↩︎ Exam trap 1
      “prompted to authenticate using the pre-existing method, then prompted to configure a new, allowed method.”
      ↩︎ Checkpoint
      “recover the ability to sign in by temporarily disabling MFA or by helping the user set up a new MFA method”
      ↩︎ Checkpoint
    2. 2.
      “A SAML2 security integration replaces the deprecated SAML_IDENTITY_PROVIDER account parameter.”
      ↩︎ Configuring SAML2 single sign-on
      “An IdP-initiated SSO does not require configuration in Snowflake.”
      ↩︎ Configuring SAML2 single sign-on
      “Snowflake never exports or makes its private key available.”
      ↩︎ Configuring SAML2 single sign-on
      “Note that /fed/login is appended to the URL for the SAML2_SNOWFLAKE_ACS_URL property.”
      ↩︎ Exam trap 2
      “refresh the IdP’s configuration settings without having to change any of the integration’s parameters.”
      ↩︎ Exam trap 3
      “This string appears on the Snowflake login page so users can access the IdP.”
      ↩︎ Checkpoint
      “Snowflake uses the metadata URL to dynamically obtain the IdP’s configuration settings, including its certificate.”
      ↩︎ Checkpoint
    3. 3.
      “Snowflake’s integration with External OAuth servers is cloud-agnostic.”
      ↩︎ External OAuth, and troubleshooting failed SSO
      “On verification, the authorization server sends a JSON Web Token (that is, an OAuth token) to the client application.”
      ↩︎ Checkpoint
    4. 4.
      “Topics related to using Snowflake OAuth and External OAuth to connect to Snowflake.”
      ↩︎ External OAuth, and troubleshooting failed SSO

    Continue to page 2 of 2

    Snowflake Key Pairs, PATs, Secrets, Session Policies and Threat Protection

    Spotted a mistake, or was something unclear? Tell us.