What you will be able to do
- Decide which users must enroll in Snowflake MFA and restrict the allowed MFA methods with an authentication policy
- Require Snowflake MFA on top of IdP authentication for SSO users
- Recover a locked-out user and set up break-glass access with one-time passcodes
- Configure a SAML2 security integration, including SP-initiated login, signing, encryption and NameID format
- Trace the External OAuth flow and diagnose failed SAML sign-ins
Key concept
Authentication policy — An authentication policy is a Snowflake policy object that you set on the account or on a user. It decides how that principal may sign in: which authentication methods and security integrations are allowed, whether MFA enrollment is required, and which MFA methods are accepted.
1.Snowflake-managed MFA: who enrolls, and with which authenticator
Snowflake-managed MFA protects one kind of sign-in: a human user who signs in with a password. After entering the password, an enrolled user must also present a second factor. Service users can't use MFA. They need another way to authenticate, such as the key pairs and tokens covered in the programmatic-access lesson.
Whether enrollment is required depends on when the account was created. An account that existed before the 2024_08 behavior change bundle was enabled must be configured to require MFA. An account created after that bundle requires MFA by default for every human user who signs in with a password. In those newer accounts, you can relax the requirement by setting an authentication policy with MFA_ENROLLMENT=OPTIONAL on the account. Even then, Snowsight password users still need MFA, and Snowflake describes this opt-out as temporary because single-factor password sign-ins are being deprecated.
| Method | What it is | Design note from the docs |
|---|---|---|
| Passkey (PASSKEY) | A passkey that can be stored and accessed in a variety of ways, such as on a YubiKey | Recommended for its security and usability |
| Authenticator app (TOTP) | An app that generates a time-based one-time passcode | Allowed by default |
| Duo | Authenticating with Duo | Unlike the other methods, Duo is not replicated |
Administrators choose which of these methods are allowed with the MFA_POLICY clause of an authentication policy. The policy below requires enrollment and accepts passkeys and authenticator apps, but not Duo:
CREATE AUTHENTICATION POLICY mfa_policy
MFA_ENROLLMENT = REQUIRED
MFA_POLICY = (ALLOWED_METHODS = ('PASSKEY', 'TOTP'));Checkpoint 1 of 8· Check yourself
You apply the policy above. A user who enrolled only Duo earlier then signs in. What happens?
When a method becomes prohibited, the user is not locked out. They use the method they already have one more time and are then made to configure an allowed one.
“prompted to authenticate using the pre-existing method, then prompted to configure a new, allowed method.”Source: docs.snowflake.com
Checkpoint 2 of 8· Exam question
A security researcher publishes a breach dump, and Snowflake's leaked password protection matches the current password of a PERSON user in your account. What does Snowflake do on its own?
Correct answer: C — It confirms the password still works, unsets it so password sign-in stops, and emails the affected user and account administrators.
- A. Incorrect: Snowflake does not create or attach authentication policies for this feature; the protection works by unsetting the password itself.
- B. Incorrect: Snowflake does not disable the user or kill sessions; only the password is removed, so SSO or key-pair sign-in continues to work.
- C. Correct: the service verifies the password still authenticates, then unsets it and notifies contacts; the user can still use other methods such as SSO and is told to request a reset link.
- D. Incorrect: the leaked password is not left usable. It is unset immediately, rather than forcing a change at next login.
Sources1
2.Externally-managed MFA for SSO users
Externally-managed MFA means that the IdP enforces the second factor, not Snowflake. This is the default for SAML and OIDC users. If you don't trust that boundary for high-privilege users, an authentication policy can add Snowflake MFA after IdP sign-in. The policy lists the allowed methods and the security integrations they may use. It requires enrollment, and the MFA_POLICY clause sets ENFORCE_MFA_ON_EXTERNAL_AUTHENTICATION. The example below is named for its typical use, administrators who must pass both factors.
Checkpoint 3 of 8· Fill the gap
Which MFA_POLICY setting makes SSO users complete Snowflake MFA after the IdP sign-in?
CREATE AUTHENTICATION POLICY ACCOUNTADMIN_DOUBLE_MFA
AUTHENTICATION_METHODS = ('PASSWORD', 'SAML', 'OIDC')
SECURITY_INTEGRATIONS = ('<SAML OR OIDC SECURITY INTEGRATIONS>')
MFA_ENROLLMENT = 'REQUIRED'
MFA_POLICY=( ? ='ALL');MFA_ENROLLMENT alone only covers password sign-ins. Setting ENFORCE_MFA_ON_EXTERNAL_AUTHENTICATION='ALL' extends Snowflake MFA to users who authenticate externally through SAML or OIDC.
Source: docs.snowflake.comSources1
3.Recovering locked-out users and break-glass access
Lockouts happen when a user loses the device that holds their second factor. Administrators have two ways to recover the user. To have the user enroll a new factor, run ALTER USER joe ENROLL MFA;. If the user has a verified email, Snowflake emails them a prompt. If not, Snowflake returns a URL that the administrator passes on. To allow a single-factor password sign-in for a limited window, run ALTER USER joe SET MINS_TO_BYPASS_MFA = 30;. Before re-enrolling, list the user's factors with SHOW MFA METHODS FOR USER joe, then drop the one that is gone with ALTER USER … REMOVE MFA METHOD.
Break glass covers a different failure: the usual sign-in path is unavailable, for example because the IdP is down. Snowflake's pattern is a dedicated user whose password is kept in a key vault together with pre-generated one-time passcodes (OTPs). Signing in with the password plus an OTP still meets the MFA requirement. Each OTP works only once. Generating a new batch invalidates every earlier passcode, which is also how you revoke them all at once.
ALTER USER breakglass_user ADD MFA METHOD OTP COUNT = 5;Checkpoint 4 of 8· Match them up
Match each statement to what it does
Tap a term, then the definition that fits it.
Re-enrollment and bypass are the two lockout remedies. OTP generation supports break-glass access, and REMOVE MFA METHOD revokes a single factor.
“recover the ability to sign in by temporarily disabling MFA or by helping the user set up a new MFA method”Source: docs.snowflake.com
Sources1
4.Configuring SAML2 single sign-on
SSO moves the first factor to your IdP. Snowflake represents the trust relationship as a SAML2 security integration, which replaces the deprecated SAML_IDENTITY_PROVIDER account parameter. The recommended way to describe the IdP is METADATA_URL. With it, Snowflake fetches the IdP's settings, including its certificate, dynamically, so you don't have to paste them in by hand.
On the service-provider side, the two Snowflake URLs must exactly match the account URL you registered at the IdP. If you omit them, they default to the account's legacy URL. Snowflake appends /fed/login to the ACS URL. The example uses a private-connectivity account URL:
CREATE SECURITY INTEGRATION my_idp
TYPE = saml2
ENABLED = true
METADATA_URL = 'https://integrator-26580.okta.com/app/ex2kbcS30N697/sso/saml/metadata'
SAML2_SNOWFLAKE_ISSUER_URL = 'https://<orgname>-<account_name>.privatelink.snowflakecomputing.com'
SAML2_SNOWFLAKE_ACS_URL = 'https://<orgname>-<account_name>.privatelink.snowflakecomputing.com/fed/login';| Property | Effect |
|---|---|
| SAML2_ENABLE_SP_INITIATED | Enables Snowflake-initiated SSO (IdP-initiated SSO needs no Snowflake configuration) |
| SAML2_SP_INITIATED_LOGIN_PAGE_LABEL | Text that identifies the IdP on the Snowflake login page |
| SAML2_SNOWFLAKE_X509_CERT | Snowflake's public certificate; the IdP uses it to encrypt assertions and verify signed requests |
| SAML2_SIGN_REQUEST | Signs SAML requests so the IdP can verify they come from Snowflake |
| SAML2_REQUESTED_NAMEID_FORMAT | The NameID format requested from the IdP; defaults to emailAddress |
Snowflake decrypts encrypted assertions with its own private key and never exports that key. By default, the certificate is self-signed. If you need a CA-issued certificate, generate a CSR with SYSTEM$GENERATE_SAML_CSR and upload the issued certificate into SAML2_SNOWFLAKE_X509_CERT.
Checkpoint 5 of 8· Check yourself
Users should be able to start SSO from a button on the Snowflake login page. What do you configure?
Only IdP-initiated SSO works without configuration. Snowflake-initiated SSO has to be enabled, and the label is the string displayed on the login page.
“This string appears on the Snowflake login page so users can access the IdP.”Source: docs.snowflake.com
Checkpoint 6 of 8· Exam question
Your SOC wants evidence that Snowflake's malicious IP protection is blocking sign-in attempts from anonymizing infrastructure. You also want to relax blocking for one low-risk category used by contractors. Which statements are accurate? (Select all that apply.)(Select 3)
Correct answers: A, B, E — SYSTEM$OPT_OUT_MALICIOUS_IP_PROTECTION_BY_CATEGORY can exclude low-risk categories from blocking, while high-risk categories stay blocked.; Blocking is driven by a curated threat-intelligence list, so it is enabled by default and covers categories such as TOR exit nodes and anonymous proxies.; Blocked attempts show up in ACCOUNT_USAGE.LOGIN_HISTORY with IS_SUCCESS = NO and LOGIN_DETAILS carrying a BLOCKED result plus the risk class and IP categories.
- A. Correct: the opt-out function applies to low-risk categories only; high-risk categories remain blocked.
- B. Correct: Snowflake maintains a curated list (anonymous VPNs, proxies, malicious behavior, TOR exits) and blocks matches by default.
- C. Incorrect: no account parameter turns this on. It is enabled by default and independent of network policies.
- D. Incorrect: a network policy allowlist is a separate control and does not exempt an address from the curated-list blocking.
- E. Correct: blocked attempts are recorded in LOGIN_HISTORY, with details showing the BLOCKED result and category information.
Sources2
5.External OAuth, and troubleshooting failed SSO
OAuth is the other IdP-driven path, used mostly by applications that act for a user. Snowflake supports both Snowflake OAuth and External OAuth. The sources for this lesson cover only the External OAuth flow, so the configuration parameters of Snowflake OAuth integrations are not described here. External OAuth does not depend on where the authorization server runs, whether in any cloud or on-premises. You set up trust once with a security integration. After that, every access attempt follows a fixed sequence.
Checkpoint 7 of 8· Put it in order
Put the External OAuth flow in order
- 1.The authorization server sends a JSON Web Token to the client application
- 2.Snowflake validates the token
- 3.Configure the authorization server and a Snowflake security integration to establish trust
- 4.The Snowflake driver passes a connection string containing the OAuth token
- 5.Snowflake performs a user lookup and starts a session
- 6.The user's BI application attempts to verify the user
Trust is set up once. The token is issued to the client before Snowflake ever sees it, and Snowflake validates the token before it looks up the user.
“On verification, the authorization server sends a JSON Web Token (that is, an OAuth token) to the client application.”Source: docs.snowflake.com
A failed SAML sign-in gives the user a UUID. Pass the UUID to SYSTEM$GET_LOGIN_FAILURE_DETAILS to get the error code, then look the code up:
SELECT JSON_EXTRACT_PATH_TEXT(SYSTEM$GET_LOGIN_FAILURE_DETAILS('eb55b777-50a4-4db5-b231-9ee457fb3981'), 'errorCode');| Code | Error | Meaning |
|---|---|---|
| 390133 | SAML_RESPONSE_INVALID | Response invalid, most likely malformed |
| 390165 | SAML_RESPONSE_INVALID_SIGNATURE | The response contains an invalid Signature |
| 390168 | SAML_RESPONSE_INVALID_DESTINATION | Destination does not match a valid URL on the account |
| 390169 | SAML_RESPONSE_INVALID_AUDIENCE | Not exactly one audience, or the audience URL is unexpected |
Destination and audience errors usually mean the issuer or ACS URLs don't match what the IdP was given. Signature errors usually follow an IdP certificate change. If the integration uses METADATA_URL, ALTER SECURITY INTEGRATION … REFRESH METADATA_URL re-reads the IdP's settings without changing any other parameter.
Checkpoint 8 of 8· Check yourself
After the IdP replaces its signing certificate, SAML sign-ins fail with error 390165. The integration was built with METADATA_URL. What is the least disruptive fix?
The metadata URL supplies the IdP's certificate. Refreshing it picks up the new certificate and changes none of the integration's parameters. Snowflake's own certificate is not the one that changed.
“Snowflake uses the metadata URL to dynamically obtain the IdP’s configuration settings, including its certificate.”Source: docs.snowflake.com
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Requiring MFA_ENROLLMENT also forces SSO users through Snowflake MFA.Why is that wrong?
By default, Snowflake leaves MFA for SSO users to the IdP. Snowflake MFA after IdP sign-in only applies when an authentication policy sets ENFORCE_MFA_ON_EXTERNAL_AUTHENTICATION.
Covered in Externally-managed MFA for SSO users
2.SAML2_SNOWFLAKE_ACS_URL is just the plain account URL.Why is that wrong?
The ACS URL is the account URL with /fed/login appended, and it must match the URL configured at the IdP.
Covered in Configuring SAML2 single sign-on
3.Rotating the IdP certificate means rebuilding the SAML2 integration.Why is that wrong?
When the integration uses METADATA_URL, a REFRESH METADATA_URL re-reads the IdP's settings, including its certificate, without changing any parameters.
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“MFA is intended for human users who authenticate with a password. Service users must use another form of authentication.”
↩︎ Snowflake-managed MFA: who enrolls, and with which authenticator“Passkeys are recommended due to their security and usability.”
↩︎ Snowflake-managed MFA: who enrolls, and with which authenticator“Password users who use Snowsight must still use MFA, but MFA isn’t required for other interfaces.”
↩︎ Snowflake-managed MFA: who enrolls, and with which authenticator“Snowflake relies on the identity provider (IdP) to enforce MFA or some other strong authentication method.”
↩︎ Externally-managed MFA for SSO users“After an OTP is used to authenticate, it is invalidated and can’t be used to authenticate again.”
↩︎ Recovering locked-out users and break-glass access“Previously generated OTPs are invalidated.”
↩︎ Recovering locked-out users and break-glass access“you can use an authentication policy to control which MFA methods can be used as a second factor of authentication.”
↩︎ Key concept“By default, Snowflake doesn’t require MFA for users who authenticate with single sign-on (SSO).”
↩︎ Exam trap 1“prompted to authenticate using the pre-existing method, then prompted to configure a new, allowed method.”
↩︎ Checkpoint“recover the ability to sign in by temporarily disabling MFA or by helping the user set up a new MFA method”
↩︎ Checkpoint - 2.
“A SAML2 security integration replaces the deprecated SAML_IDENTITY_PROVIDER account parameter.”
↩︎ Configuring SAML2 single sign-on“An IdP-initiated SSO does not require configuration in Snowflake.”
↩︎ Configuring SAML2 single sign-on“Snowflake never exports or makes its private key available.”
↩︎ Configuring SAML2 single sign-on“Note that /fed/login is appended to the URL for the SAML2_SNOWFLAKE_ACS_URL property.”
↩︎ Exam trap 2“refresh the IdP’s configuration settings without having to change any of the integration’s parameters.”
↩︎ Exam trap 3“This string appears on the Snowflake login page so users can access the IdP.”
↩︎ Checkpoint“Snowflake uses the metadata URL to dynamically obtain the IdP’s configuration settings, including its certificate.”
↩︎ Checkpoint - 3.
“Snowflake’s integration with External OAuth servers is cloud-agnostic.”
↩︎ External OAuth, and troubleshooting failed SSO“On verification, the authorization server sends a JSON Web Token (that is, an OAuth token) to the client application.”
↩︎ Checkpoint - 4.https://docs.snowflake.com/en/guides-overview-secureOfficial docs
“Topics related to using Snowflake OAuth and External OAuth to connect to Snowflake.”
↩︎ External OAuth, and troubleshooting failed SSO - 5.https://docs.snowflake.com/en/user-guide/errors-samlOfficial docs
“The SAML response contains an invalid Signature.”
↩︎ External OAuth, and troubleshooting failed SSO