Loading
Prepare for Email to Become the Default Login ExperienceRead More
Intermittent freezing when using using certain browser versionsRead More
Secure Your Salesforce Org
MFA Verification Methods for Direct Salesforce Login

MFA Verification Methods for Direct Salesforce Login

The multi-factor authentication (MFA) login process requires users to provide an identity verification method in addition to their username and password. Salesforce MFA functionality supports several types of verification methods, including passkeys (built-in authenticators and security keys) and authenticator apps. You can control which methods are available to your users.

Important
Important

Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

Let's look at the benefits and considerations for each type of verification method supported by Salesforce products.

Passkeys Security Keys (Passkeys) Salesforce Authenticator Third-Party Authenticator Apps
Operating system-level authentication that verifies identity with fingerprint, iris, or facial recognition scan, or a PIN or password. Physical devices that use public-key cryptography. A smart and simple mobile app that users can easily connect to their Salesforce accounts. Apps that generate unique, temporary verification codes based on the OATH TOTP algorithm (specified in RFC 6238).

Security Tier:

Phishing-resistant

Security Tier:Phishing-resistant Security Tier:Standard Security Tier:Standard

Form Factor:

Available via a device's built-in authenticator service (for example, Windows Hello, Touch ID, and Face ID)

Form Factor:

USB, Lightning, and NFC devices that support the WebAuthn and U2F standards

Form Factor:

Mobile app for iOS and Android

Form Factor:

Mobile, desktop, and browser extension apps available for multiple operating systems

User Experience:

  • Fast and easy to use.
  • No apps required.
  • A great choice if users need a non-mobile option.
  • Strong public-key cryptography that's unique to the user's account.

User Experience:

  • Fast and easy to use.
  • Recognizes and denies fraudulent requests.
  • A great choice if users need a non-mobile option.
  • Connectivity isn't required.
  • No batteries needed.

User Experience:

  • Delivers push notifications to users' phones for fast access.
  • See real-time details to confirm request validity.
  • Deny fraudulent requests with a tap.
  • Automates authentication from trusted locations
  • Generates TOTP codes that work if connectivity isn't available.

User Experience:

  • A wide variety of apps, including non-mobile options, to choose from.
  • Codes work if connectivity isn't available.

Considerations:

  • Device, operating system, and browser must support FIDO2 WebAuthn standard.
  • Built-in authenticator service must be enabled and set up before MFA registration.
  • Works only for a single device.
  • Supported scanner required for biometric identification.

Considerations:

  • Requires browser support (limited for U2F).
  • Users could leave keys unattended or plugged in all the time.
  • Operational overhead for purchasing, stocking, and distributing devices to users.

Considerations:

  • Requires a mobile device.

Considerations:

  • Typing errors are possible when manually entering codes.
  • Invalid codes are possible if mobile device clock gets out of sync with Salesforce.
Cost: Starts around $25 for biometric peripherals, if needed Cost: Starts around $20 Cost: Free Cost: Free and paid options
Learn More Learn More Learn More Learn More

Notes:

‣ If users don't want to use a mobile authenticator app, consider a TOTP desktop authenticator app or browser extension.

‣ Security keys that use the NFC form factor aren't supported in products built on the Salesforce Platform.

‣ WebAuthn-compatible security keys aren't supported in non-Chromium versions of the Edge browser.

‣ Built-in authenticators are supported in products built on the Salesforce Platform, Heroku, Marketing Cloud Intelligence, MuleSoft Anypoint Platform, and Tableau Cloud.

  • Salesforce Authenticator for MFA
    The Salesforce Authenticator mobile app is a verification method that can be used as a second factor for multi-factor authentication (MFA) logins. The app is free and simple to use.
  • Passkeys for MFA
    Multi-factor authentication (MFA) verification is easy with a passkey (formerly known as built-in authenticator) service such as Windows Hello, Touch ID or Face ID, or a password manager. Users can quickly verify their identity with a fingerprint, iris, or facial recognition scan (or in some cases, with a PIN or password that the user sets up in their device's operating system). Passkeys provide secure, fast, easy login. They satisfy the phishing-resistant MFA requirement for privileged users.
  • Troubleshoot Passkey Issues
    When employee users log in and register for multi-factor authentication (MFA), passkeys are the default option. Identify and resolve issues with passkey prompts, setup, login, and more.
  • Security Keys (Passkeys) for MFA
    Security keys are physical passkeys. They're small, USB or NFC devices that are easy to use for multi-factor authentication (MFA) logins because there's nothing to install and no codes to enter. This type of method is a great option if users don't have a mobile device or if phones aren't allowed where your users work (such as a PCI-compliant service center). Security keys require a supported browser to act as an intermediary between the key and your Salesforce product. Popular security keys include the YubiKey from Yubico and the Titan Security Key from Google. Security keys satisfy the phishing-resistant MFA requirement for privileged users.
  • Third-Party Authenticator Apps for MFA
    Salesforce multi-factor authentication (MFA) supports the use of third-party authenticator apps that generate time-based one-time password (TOTP) codes. There are many mobile, desktop, and browser extension apps available, including free versions. Some popular options include Google Authenticator, Microsoft Authenticator, Authy, and password managers such as LastPass and 1Password. Third-party authenticator apps are considered standard-strength verification methods, so they can satisfy the MFA requirement for non-privileged users.
 
Loading
Salesforce Help | Article