Phishing-Resistant MFA Requirement for Privileged Users
Salesforce requires multi-factor authentication (MFA) for all employee logins to
Salesforce products. For internal user accounts that have a higher level of access, such as
admin accounts, Salesforce requires extra security: users must complete MFA using a
phishing-resistant method, such as a passkey or security key. This requirement applies to direct
and single sign-on (SSO) logins for active production and sandbox orgs.
Required Editions
Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
Phishing is a social engineering technique used to acquire sensitive information.
Phishers masquerade as a trustworthy person or company and convince users to give away
sensitive information. For example, phishers convince users to enter their password on a
fake website. Phishing-resistant MFA methods prevent these attacks because they're bound to
one website, the domain for your Salesforce org. They can't be used on a phisher's
illegitimate website. Phishing-resistant methods include passkeys, which let users log in
with Touch or Face ID, Windows Hello, password managers, or security keys.
For the
phishing-resistant requirement, an internal user is considered privileged if they meet any
of these criteria:
System Administrator profile OR
Author Apex user permission OR
Customize Application user permission OR
Modify All Data user permission OR
View All Data user permission
For direct logins, Salesforce requires these users to complete MFA using a passkey
(built-in
authenticator or security key). With the enforcement of phishing-resistant MFA,
privileged users who don't have a passkey are prompted to set one up to log in. To save time
and clicks, you can also enable passwordless login with passkeys, which allows users
to log in with just their username and passkey. This is the fastest and easiest way to log
in to Salesforce directly.
For SSO logins, you can meet the requirement by using a
phishing-resistant method from your SSO provider. For example, if your SSO provider is Okta,
users can log in and complete MFA in Okta before being redirected to Salesforce. To use this
option, your SSO provider must send properly formatted authentication signals that
Salesforce recognizes as phishing-resistant. Otherwise, users are required to create a
passkey before they can finish logging in to Salesforce. See MFA with an SSO Identity Provider.
Phishing-resistant MFA doesn't
work with automation or integration user accounts. Consider removing permissions if possible
and completing MFA challenges
programmatically with a third-party authenticator app. For use cases that require
automation users to have privileged permissions, contact Salesforce Customer
Support.
Phishing-resistant MFA is required only for users who access the Salesforce
user interface (UI). It isn't required for API logins.
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.