Loading
Upcoming Mandatory Changes to Public Key Infrastructure (PKI)Read More
Salesforce Enforces New Security Requirements in Summer 2026Read More
Secure Your Salesforce Org
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Enable Security Keys (Passkeys) for Identity Verification in Salesforce Orgs

          Enable Security Keys (Passkeys) for Identity Verification in Salesforce Orgs

          Allow your users to verify their identity for multi-factor authentication (MFA) or device activation with WebAuthn (FIDO2) or Universal Second Factor (U2F) security keys. After you enable this method, users can register a security key so it’s connected to their Salesforce account. Security keys satisfy the phishing-resistant MFA requirement for privileged users. After MFA requirements are enforced in your org, security keys are enabled by default.

          Required Editions

          Available in: both Salesforce Classic and Lightning Experience
          Available in: all editions
          User Permissions Needed
          To enable security keys:

          Customize Application

          AND

          Manage Users

          Important
          Important

          Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

          In orgs created in Summer ‘25 and later, this setting is enabled by default.

          After phishing-resistant MFA is enforced, these changes take effect.

          • This setting applies only to internal users who don't have privileged permissions. Security keys are automatically enabled for users with privileged permissions (the System Administrator profile or the Author Apex, Customize Application, Modify All Data, or View All Data user permissions) and can't be turned off.
          • The UI label for this setting changes to Let users verify their identity with a physical security key (passkey) such as U2F or WebAuthn.
          1. From Setup, use the Quick Find box to find and select Identity Verification.
          2. Select Let users verify their identity with a physical security key (U2F or WebAuthn).
          3. Save your changes.
           
          Loading
          Salesforce Help | Article