Loading
Upcoming Mandatory Changes to Public Key Infrastructure (PKI)Read More
Secure Your Salesforce Org
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          MFA Verification Methods for Direct Salesforce Login

          MFA Verification Methods for Direct Salesforce Login

          The multi-factor authentication (MFA) login process requires users to provide an identity verification method in addition to their username and password. Salesforce MFA functionality supports several types of verification methods, including passkeys (built-in authenticators and security keys) and authenticator apps. You can control which methods are available to your users.

          Important
          Important

          Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

          Let's look at the benefits and considerations for each type of verification method supported by Salesforce products.

          Built-In Authenticators (Passkeys) Security Keys (Passkeys) Salesforce Authenticator Third-Party Authenticator Apps
          Operating system-level authentication that verifies identity with fingerprint, iris, or facial recognition scan, or a PIN or password. Physical devices that use public-key cryptography. A smart and simple mobile app that users can easily connect to their Salesforce accounts. Apps that generate unique, temporary verification codes based on the OATH TOTP algorithm (specified in RFC 6238).

          Security Tier:

          Phishing-resistant

          Security Tier:Phishing-resistant Security Tier:Standard Security Tier:Standard

          Form Factor:

          Available via a device's built-in authenticator service (for example, Windows Hello, Touch ID, and Face ID)

          Form Factor:

          USB, Lightning, and NFC devices that support the WebAuthn and U2F standards

          Form Factor:

          Mobile app for iOS and Android

          Form Factor:

          Mobile, desktop, and browser extension apps available for multiple operating systems

          User Experience:

          • Fast and easy to use.
          • No apps required.
          • A great choice if users need a non-mobile option.
          • Strong public-key cryptography that's unique to the user's account.

          User Experience:

          • Fast and easy to use.
          • Recognizes and denies fraudulent requests.
          • A great choice if users need a non-mobile option.
          • Connectivity isn't required.
          • No batteries needed.

          User Experience:

          • Delivers push notifications to users' phones for fast access.
          • See real-time details to confirm request validity.
          • Deny fraudulent requests with a tap.
          • Automates authentication from trusted locations
          • Generates TOTP codes that work if connectivity isn't available.

          User Experience:

          • A wide variety of apps, including non-mobile options, to choose from.
          • Codes work if connectivity isn't available.

          Considerations:

          • Device, operating system, and browser must support FIDO2 WebAuthn standard.
          • Built-in authenticator service must be enabled and set up before MFA registration.
          • Works only for a single device.
          • Supported scanner required for biometric identification.

          Considerations:

          • Requires browser support (limited for U2F).
          • Users could leave keys unattended or plugged in all the time.
          • Operational overhead for purchasing, stocking, and distributing devices to users.

          Considerations:

          • Requires a mobile device.

          Considerations:

          • Typing errors are possible when manually entering codes.
          • Invalid codes are possible if mobile device clock gets out of sync with Salesforce.
          Cost: Starts around $25 for biometric peripherals, if needed Cost: Starts around $20 Cost: Free Cost: Free and paid options
          Learn More Learn More Learn More Learn More

          Notes:

          ‣ If users don't want to use a mobile authenticator app, consider a TOTP desktop authenticator app or browser extension.

          ‣ Security keys that use the NFC form factor aren't supported in products built on the Salesforce Platform.

          ‣ WebAuthn-compatible security keys aren't supported in non-Chromium versions of the Edge browser.

          ‣ Built-in authenticators are supported in products built on the Salesforce Platform, Heroku, Marketing Cloud Intelligence, MuleSoft Anypoint Platform, and Tableau Cloud.

          • Salesforce Authenticator for MFA
            The Salesforce Authenticator mobile app is a verification method that can be used as a second factor for multi-factor authentication (MFA) logins. The app is free and simple to use.
          • Built-In Authenticators (Passkeys) for MFA
            Multi-factor authentication (MFA) verification is easy with a built-in authenticator (passkey) service such as Windows Hello, Touch ID, or Face ID. Users can quickly verify their identity with a fingerprint, iris, or facial recognition scan (or in some cases, with a PIN or password that the user sets up in their device's operating system). Built-in authenticators streamline the MFA requirement because they rely on built-in mechanisms rather than users needing a separate authenticator app or physical security key. Built-in authenticators satisfy the phishing-resistant MFA requirement for privileged users.
          • Security Keys (Passkeys) for MFA
            Security keys are physical passkeys. They're small, USB or NFC devices that are easy to use for multi-factor authentication (MFA) logins because there's nothing to install and no codes to enter. This type of method is a great option if users don't have a mobile device or if phones aren't allowed where your users work (such as a PCI-compliant service center). Security keys require a supported browser to act as an intermediary between the key and your Salesforce product. Popular security keys include the YubiKey from Yubico and the Titan Security Key from Google. Security keys satisfy the phishing-resistant MFA requirement for privileged users.
          • Third-Party Authenticator Apps for MFA
            Salesforce multi-factor authentication (MFA) supports the use of third-party authenticator apps that generate time-based one-time password (TOTP) codes. There are many mobile, desktop, and browser extension apps available, including free versions. Some popular options include Google Authenticator, Microsoft Authenticator, Authy, and password managers such as LastPass and 1Password. Third-party authenticator apps are considered standard-strength verification methods, so they can satisfy the MFA requirement for non-privileged users.
           
          Loading
          Salesforce Help | Article