You are here:
Determine Business and User Needs for MFA
Even though multi-factor authentication (MFA) is required to access production orgs and sandboxes, we recommend that you look for ways to optimize the experience for your users. If your company accesses Salesforce via single sign-on (SSO), understanding your business and user needs gives you insights to help define your MFA implementation. To help determine the most suitable MFA verification methods for your users, review potential requirements and important considerations.
Required Editions
| Available in: both Salesforce Classic and Lightning Experience |
| Available in: all editions |
Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.
Here are some questions and potential requirements to consider.
| Existing Authentication Solutions | Does your company use an existing MFA solution, like Okta or Duo, for other systems? If your Salesforce users already use MFA to log in to other applications, see whether you can integrate your Salesforce products with the same solution. Doing so can minimize friction and change management needs because users already use MFA. Are your Salesforce products integrated with an SSO solution? If so, you can use your SSO provider's MFA service (provided that the provider sends the appropriate authentication signals to Salesforce). Or, you can use the MFA service included with Salesforce to satisfy the requirement. |
| Device Requirements | Consider whether your industry's or company's mobile device policies place any constraints on your MFA implementation. For example, to satisfy the phishing-resistant MFA requirement for admin users, does your company allow hardware security keys? Or should you satisfy the requirement with passkeys built into users' devices, such as Touch ID or Windows Hello? |
| User Considerations | Understand how MFA can impact the various roles and teams at your company. For example:
We recommend supporting multiple verification methods in your implementation, so that each person can choose the options that work best for them. |
| Shared Salesforce Credentials | Sharing user credentials with multiple users isn't allowed. MFA is incompatible with this practice because Salesforce requires each user to register and connect a unique verification method to their Salesforce account before they can log in. If multiple users in your org share a single account, only one person can log in when MFA is turned on. Resolve any shared accounts or credentials that are in use. Make sure you have enough licenses to set up separate accounts for each person who accesses your Salesforce org. If you need help with setting up unique user accounts, contact your Account Executive or Sales team. Or refer to Salesforce Checkout and Self Service to Manage Your Account. |
| Budget and Timeline | Consider your budget for operational and user support functions. Salesforce products provide MFA at no extra cost, and the Salesforce Authenticator app is free. But if a mobile app option doesn't work for some or all users, consider setting aside some budget to purchase and distribute security keys. |
| Security Requirements | Make sure that you understand MFA requirements for internal users, including the phishing-resistant MFA requirement for privileged users. Work with your security and IT teams to understand how MFA aligns with your company's security objectives and requirements. Understand whether any enterprise mandates are in place, and what kinds of application testing or evaluation processes you must follow. |
| Legal and Regulatory Requirements | What are your company's legal commitments to customers and other stakeholders around how your users authenticate to your systems? Also consider local and other regulatory requirements and how they can impact your MFA implementation. For example, some regulatory requirements include restrictions on downloading applications to certain devices or bringing mobile devices into certain environments. |
| Compliance Requirements | What kinds of audit requirements does an MFA implementation affect or trigger? Are you beginning any new compliance regimes in the next 12 months that could be affected by your MFA implementation? |
