Loading
Prepare for Email to Become the Default Login ExperienceRead More
Intermittent freezing when using using certain browser versionsRead More
Secure Your Salesforce Org
Learn What MFA Is and Why It's So Important

Learn What MFA Is and Why It's So Important

As security threats grow more common, it's increasingly important to implement strong measures to protect your Salesforce data, your business, and ultimately, your customers. Usernames and passwords alone are no longer sufficient for guarding against unauthorized account access. Multi-factor authentication (MFA) is one of the simplest, most effective ways to enhance the security of your login process because it requires multiple pieces of evidence to prove a user is who they say they are. Salesforce requires MFA for all internal users, such as employees, who access your Salesforce org. Users with privileged access to Salesforce, such as admins, are required to use phishing-resistant verification methods to complete MFA.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
Important
Important

Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

How MFA Works

Check out this video for a visual tutorial of how MFA works.

MFA ensures a user's identity by requiring multiple "factors" during the login process.

  • The first factor is something that a user knows — their username and password.
  • After that, the user is prompted for a second factor that's in their possession — an identity verification method such as an authenticator app or security key.

By tying user access to several different types of factors, it's harder for a bad actor to gain entry to your Salesforce org. Even if a user's password is compromised, the odds are low that an attacker can guess or impersonate a factor that a user physically possesses.

Each user must spend a few minutes registering at least one verification method so that it's connected to their Salesforce account. The first time a user logs in after MFA is turned on, they're asked to complete this task. On-screen prompts guide users through the simple process.

  • Understand MFA Requirements
    To protect users from security threats such as phishing, credential stuffing, and account takeovers, Salesforce requires multi-factor authentication (MFA) for all employee logins to Salesforce products. Understand MFA requirements based on the type of org, the type of user, and the user's level of access.
  • Phishing-Resistant MFA Requirement for Privileged Users
    Salesforce requires multi-factor authentication (MFA) for all employee logins to Salesforce products. For internal user accounts that have a higher level of access, such as admin accounts, Salesforce requires extra security: users must complete MFA using a phishing-resistant method, such as a passkey or security key. This requirement applies to direct and single sign-on (SSO) logins for active production and sandbox orgs.
  • MFA Verification Method Tiers
    The multi-factor authentication (MFA) login process requires users to provide an identity verification method in addition to their username and password. Salesforce supports several types of verification methods, including passkeys (built-in authenticators and security keys) and authenticator apps. Some verification methods are stronger than others. Salesforce requires users with privileged permissions, such as admins, to use more secure methods.
  • Products That Support MFA
    All products that are built on the Salesforce Platform provide multi-factor authentication (MFA) functionality at no additional cost. If you aren’t sure, use this topic to verify that your product is built on the Salesforce Platform.
  • Determine Business and User Needs for MFA
    Even though multi-factor authentication (MFA) is required to access production orgs and sandboxes, we recommend that you look for ways to optimize the experience for your users. If your company accesses Salesforce via single sign-on (SSO), understanding your business and user needs gives you insights to help define your MFA implementation. To help determine the most suitable MFA verification methods for your users, review potential requirements and important considerations.
  • Prepare Your Users for MFA
    Most people these days are familiar with some form of multi-factor authentication (MFA). But don't assume your users are going to intuitively appreciate the value of MFA, or feel comfortable completing MFA registration when they log in, without some advance awareness and preparation. Whether you're launching a new production org where MFA is on by default, turning on MFA in an org that didn't previously use it, or adding MFA to your single sign-on (SSO) process, ensure that your users are trained for MFA ahead of time. A simple change management plan goes a long way in delivering a smooth onboarding experience.
  • Test Your MFA Implementation for Salesforce Orgs
    If you test MFA ahead of time, you gain experience with the MFA registration process and can assist users with login issues. Even if Salesforce automatically enabled MFA for your existing org, it’s beneficial to evaluate how things work in a test environment.
 
Loading
Salesforce Help | Article