Skip to main content

Multi-Factor Authentication (MFA) Enforcement

What verification method you need to register — quick reference for Users and Administrators

1. Which method do I need?

This depends on your permissions, not your job title. If you can access Setup, create fields, or see records not shared with you, assume you are a privileged user and confirm with your Administrator.

Administrator / Privileged user

Standard user

You are in this group if…

You have the System Administrator profile, OR any of: Modify All Data, View All Data, Customize Application, Author Apex (via profile or permission set)

You have none of the permissions listed to the left

Requirement

Phishing-resistant MFA

MFA (passkey recommended)

Built-in authenticator

(Windows Hello, Touch ID, Face ID)

Accepted

Accepted — best choice

Physical security key

(YubiKey, Google Titan)

Accepted

Accepted

Cloud-synced passkey

(1Password, Bitwarden, iCloud)

Accepted

Accepted

Salesforce Authenticator

Not accepted

Accepted

Third-party TOTP app

(Google / Microsoft Authenticator)

Not accepted

Accepted

SMS, phone call or email code

Not accepted

Not accepted

2. Steps for users (non-administrator)

1. Log in to Salesforce with your username and password as normal.

2. Click your profile photo (top right) → Settings.

3. Go to My Personal Information → Advanced User Details.

4. Find the registration rows: Built-In Authenticator, Security Key (U2F or WebAuthn), Salesforce Authenticator, One-Time Password Generator.

5. Click Register (or Connect) next to your chosen method — a Salesforce Authenticatoris recommended — and complete the setup with these steps (MFA)

Note: If you do not register in advance, Salesforce shows a "Create a Passkey" screen at your next login and walks you through it. That prompt is genuine — it currently appears in English regardless of your language setting.

3. Steps for Salesforce Administrators

1. Enable the methods. Setup → Quick Find → Identity Verification. Turn on Let users verify their identity with a built-in authenticator and Let users verify their identity with a security key (U2F or WebAuthn).

Recommended: also enable Allow passwordless login with passkeys.

Note: once enabled these are available to all users — they cannot be restricted to admins.

2. Register your own passkey. Profile photo → Settings → My Personal Information → Advanced User Details → Register next to Built-In Authenticator and Security Key. Register two methods, not one.

4. Quick answers

  • Can we turn this off or delay it? No. Salesforce enforces it and the org-wide MFA setting becomes read-only.

  • Does it affect API integrations? Browser logins only. JWT Bearer and Client Credentials flows are unaffected; OAuth Web Server and Hybrid Token flows need a UI login, so are in scope.

  • Experience Cloud users? External, Chatter External and Chatter Free users are excluded. Internal standard-licence and Chatter Plus users are in scope, including on an Employee Community.

  • Is my biometric data sent to Salesforce? No — your fingerprint or face only unlocks a key held on your device.

  • Shared partner admin login? Share a passkey via a FIDO2-compliant password manager, or move to individual licences.

Official Salesforce references (help.salesforce.com — search by title or article number)

Did this answer your question?