1. Which method do I need?
This depends on your permissions, not your job title. If you can access Setup, create fields, or see records not shared with you, assume you are a privileged user and confirm with your Administrator.
| Administrator / Privileged user | Standard user |
You are in this group if… | You have the System Administrator profile, OR any of: Modify All Data, View All Data, Customize Application, Author Apex (via profile or permission set) | You have none of the permissions listed to the left |
Requirement | Phishing-resistant MFA | MFA (passkey recommended) |
Built-in authenticator (Windows Hello, Touch ID, Face ID) | Accepted | Accepted — best choice |
Physical security key (YubiKey, Google Titan) | Accepted | Accepted |
Cloud-synced passkey (1Password, Bitwarden, iCloud) | Accepted | Accepted |
Salesforce Authenticator | Not accepted | Accepted |
Third-party TOTP app (Google / Microsoft Authenticator) | Not accepted | Accepted |
SMS, phone call or email code | Not accepted | Not accepted |
2. Steps for users (non-administrator)
1. Log in to Salesforce with your username and password as normal.
2. Click your profile photo (top right) → Settings.
3. Go to My Personal Information → Advanced User Details.
4. Find the registration rows: Built-In Authenticator, Security Key (U2F or WebAuthn), Salesforce Authenticator, One-Time Password Generator.
5. Click Register (or Connect) next to your chosen method — a Salesforce Authenticatoris recommended — and complete the setup with these steps (MFA)
Note: If you do not register in advance, Salesforce shows a "Create a Passkey" screen at your next login and walks you through it. That prompt is genuine — it currently appears in English regardless of your language setting.
3. Steps for Salesforce Administrators
1. Enable the methods. Setup → Quick Find → Identity Verification. Turn on Let users verify their identity with a built-in authenticator and Let users verify their identity with a security key (U2F or WebAuthn).
Recommended: also enable Allow passwordless login with passkeys.
Note: once enabled these are available to all users — they cannot be restricted to admins.
2. Register your own passkey. Profile photo → Settings → My Personal Information → Advanced User Details → Register next to Built-In Authenticator and Security Key. Register two methods, not one.
4. Quick answers
Can we turn this off or delay it? No. Salesforce enforces it and the org-wide MFA setting becomes read-only.
Does it affect API integrations? Browser logins only. JWT Bearer and Client Credentials flows are unaffected; OAuth Web Server and Hybrid Token flows need a UI login, so are in scope.
Experience Cloud users? External, Chatter External and Chatter Free users are excluded. Internal standard-licence and Chatter Plus users are in scope, including on an Employee Community.
Is my biometric data sent to Salesforce? No — your fingerprint or face only unlocks a key held on your device.
Shared partner admin login? Share a passkey via a FIDO2-compliant password manager, or move to individual licences.
Official Salesforce references (help.salesforce.com — search by title or article number)
