Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Resolve MFA Access Issues for Your Users (Salesforce Orgs)

Resolve MFA Access Issues for Your Users (Salesforce Orgs)

As a Salesforce admin, part of your role is managing and maintaining user access. With multi-factor authentication (MFA) in effect for your org, it’s important to know how to resolve MFA-related access issues that users can encounter. There are three likely scenarios. A user doesn’t have access to their MFA verification method and can’t log in. A user loses or replaces a verification method and must register a new one. And the connection between a user’s registered verification method and their Salesforce account stops working. Use temporary verification codes to allow users to regain access immediately. When dealing with a broken connection or a missing verification method, revoke the connection and help the user set up a new method.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
Important
Important

Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

Important
Important If you’re the only admin for your Salesforce org and you get locked out because of MFA, contact Salesforce Customer Support for help.

Here are the recommended recovery steps for these MFA-related access issues.

Note
Note Make sure that you have the Manage Multi-Factor Authentication in User Interface permission in addition to your Salesforce admin permissions. You need this additional permission to generate temporary verification codes, disconnect verification methods from user accounts, and monitor identity verification and verification method activities in your org. See Delegate MFA Management Tasks for Salesforce Orgs.

User Forgot Their Verification Method

If a user forgot to bring their security key or the device that has their authenticator app or service, a temporary verification code gets them through the day.

User's Verification Method Is Lost or Stolen

Temporary verification codes allow a user to work until they’re able to replace their verification method. We also recommend several security-related steps to ensure a bad actor isn’t trying to use the missing method.

User's Verification Method Isn't Working or Has Been Replaced

If a user’s verification method has stopped working correctly, reset the method so the user can re-register it for MFA. These steps also apply if a user updates their security key with a new device, or replaces their mobile device or computer and has to install an MFA authenticator on the new hardware.

  • Generate a Temporary Verification Code for MFA Logins to Salesforce Orgs
    If a user forgets or loses the identity verification method that they use for multi-factor authentication (MFA), generate a temporary verification code so they can log in while you sort out the issue. You can control how long codes are valid, up to 24 hours. A user can log in multiple times with their code until it expires. Temporary verification codes are valid for MFA only. They can’t be used for device activation, when a user must verify their identity because they’re logging in from an unrecognized browser or app.
  • Expire an MFA Temporary Verification Code for Salesforce Orgs
    Expire a user’s temporary verification code when the user no longer needs it for multi-factor authentication (MFA).
  • Disconnect Identity Verification Methods that are Lost, Replaced, or Not Working (Salesforce Orgs)
    When addressing multi-factor authentication (MFA) access issues, there are situations where a Salesforce admin must disconnect a user’s current verification method from their Salesforce account. This step is necessary if a user has lost their method, or has acquired a replacement method that they want to use instead of their current one. If a user’s method stops working, disconnecting it allows the user to re-register the method and restore its connection to their account. It’s also a good practice to disconnect all of a user’s verification methods if they leave your company.
 
Loading
Salesforce Help | Article