You are here:
Resolve MFA Access Issues for Your Users (Salesforce Orgs)
As a Salesforce admin, part of your role is managing and maintaining user access. With multi-factor authentication (MFA) in effect for your org, it’s important to know how to resolve MFA-related access issues that users can encounter. There are three likely scenarios. A user doesn’t have access to their MFA verification method and can’t log in. A user loses or replaces a verification method and must register a new one. And the connection between a user’s registered verification method and their Salesforce account stops working. Use temporary verification codes to allow users to regain access immediately. When dealing with a broken connection or a missing verification method, revoke the connection and help the user set up a new method.
Required Editions
| Available in: both Salesforce Classic and Lightning Experience |
| Available in: all editions |
Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.
Here are the recommended recovery steps for these MFA-related access issues.
User Forgot Their Verification Method
If a user forgot to bring their security key or the device that has their authenticator app or service, a temporary verification code gets them through the day.
-
Issue the user a temporary verification code so they can log in. See Generate a Temporary Verification Code for MFA Logins to Salesforce Orgs.
-
Expire the temporary verification code when it's no longer needed. See Expire an MFA Temporary Verification Code for Salesforce Orgs.
User's Verification Method Is Lost or Stolen
Temporary verification codes allow a user to work until they’re able to replace their verification method. We also recommend several security-related steps to ensure a bad actor isn’t trying to use the missing method.
-
Remove the user’s current session and have the user reauthenticate. See User Sessions.
-
Disconnect the user's existing verification method. See Disconnect Identity Verification Methods that are Lost, Replaced, or Not Working (Salesforce Orgs).
-
Issue the user a temporary verification code so they can log in while you resolve their issue. See Generate a Temporary Verification Code for MFA Logins to Salesforce Orgs.
-
Audit the user’s account to see if there’s been any unusual activity. See How Your Users Are Verifying Their Identity.
-
Assist the user with acquiring a replacement device. When they have it, help them register their verification method or set up a new method. See Help Users Register MFA Verification Methods for Direct Login.
-
Expire the user's temporary verification code when it's no longer needed. See Expire an MFA Temporary Verification Code for Salesforce Orgs.
User's Verification Method Isn't Working or Has Been Replaced
If a user’s verification method has stopped working correctly, reset the method so the user can re-register it for MFA. These steps also apply if a user updates their security key with a new device, or replaces their mobile device or computer and has to install an MFA authenticator on the new hardware.
-
Issue the user a temporary verification code so they can log in while you resolve their issue. See Generate a Temporary Verification Code for MFA Logins to Salesforce Orgs.
-
Disconnect the user's existing verification method. This step is necessary because the user can’t register a replacement method of the same type until the current one is removed from Salesforce. See Disconnect Identity Verification Methods that are Lost, Replaced, or Not Working (Salesforce Orgs).
-
Help the user re-register their verification method or set up a new method. See Help Users Register MFA Verification Methods for Direct Login.
-
Expire the user's temporary verification code when it's no longer needed. See Expire an MFA Temporary Verification Code for Salesforce Orgs.
- Generate a Temporary Verification Code for MFA Logins to Salesforce Orgs
If a user forgets or loses the identity verification method that they use for multi-factor authentication (MFA), generate a temporary verification code so they can log in while you sort out the issue. You can control how long codes are valid, up to 24 hours. A user can log in multiple times with their code until it expires. Temporary verification codes are valid for MFA only. They can’t be used for device activation, when a user must verify their identity because they’re logging in from an unrecognized browser or app. - Expire an MFA Temporary Verification Code for Salesforce Orgs
Expire a user’s temporary verification code when the user no longer needs it for multi-factor authentication (MFA). - Disconnect Identity Verification Methods that are Lost, Replaced, or Not Working (Salesforce Orgs)
When addressing multi-factor authentication (MFA) access issues, there are situations where a Salesforce admin must disconnect a user’s current verification method from their Salesforce account. This step is necessary if a user has lost their method, or has acquired a replacement method that they want to use instead of their current one. If a user’s method stops working, disconnecting it allows the user to re-register the method and restore its connection to their account. It’s also a good practice to disconnect all of a user’s verification methods if they leave your company.
