Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Configure the MFA Verification Methods Available to Your Users for Salesforce Orgs

Configure the MFA Verification Methods Available to Your Users for Salesforce Orgs

Salesforce supports four identity verification methods for multi-factor authentication (MFA) and device activation: built-in authenticators, physical security keys, Salesforce Authenticator, and third-party authenticator apps. As a security best practice, require users to use phishing-resistant methods: built-in authenticators or security keys. In orgs created before Summer ’25, Salesforce Authenticator and third-party apps are automatically available to users, but a Salesforce admin must enable the options to use passkeys (built-in authenticators and physical security keys). In orgs created in Summer ’25 and later, all verification methods are allowed by default. For external users only, you can allow the use of one-time passcodes delivered via SMS text messages.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
Important
Important

Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

  • Enable Passkeys for Identity Verification in Salesforce Orgs
    With passkeys, users can log in and complete multi-factor authentication (MFA) with Touch ID or Face ID, Windows Hello, a device password, or password managers. With MFA enforcement, Salesforce automatically enables passkeys (also known as built-in authenticators) as an available verification method for all employee users. When MFA is enforced in your org, you can't turn off this setting. If MFA isn't enforced yet in your org, turn on passkeys to test them. Passkeys satisfy the phishing-resistant MFA requirement for privileged users. Users can also use security keys to complete other identity verification challenges, such as device activation.
  • Enable Security Keys for Identity Verification in Salesforce Orgs
    Security keys are small physical devices, such as YubiKeys or Titan keys, that users can use to set up passkeys for secure multi-factor authentication (MFA). With MFA enforcement, Salesforce automatically enables security keys as an available verification method for all employee users. When MFA is enforced in your org, you can't turn off this setting. If MFA isn't enforced yet in your org, turn on security keys to test them. Security keys satisfy the phishing-resistant MFA requirement for users with privileged permissions. Users can also use security keys to complete other identity verification challenges, such as device activation.
  • Use SMS as an MFA Verification Method for External Users
    If you enable multi-factor authentication (MFA) for your customer or partner Experience Cloud sites, external users can log in using one-time passcodes delivered via SMS text messages. Users need only a verified mobile number and access to their device when they log in. This option is available for external users only. External users can also verify their identity with other supported MFA verification methods such as Salesforce Authenticator built-in authenticators, security keys, and third-party authenticator apps.
 
Loading
Salesforce Help | Article