You are here:
MFA Verification Methods for Direct Salesforce Login
The multi-factor authentication (MFA) login process requires users to provide an identity verification method in addition to their username and password. Salesforce MFA functionality supports several types of verification methods, including passkeys (built-in authenticators and security keys) and authenticator apps. You can control which methods are available to your users.
Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.
Let's look at the benefits and considerations for each type of verification method supported by Salesforce products.
| Built-In Authenticators (Passkeys) | Security Keys (Passkeys) | Salesforce Authenticator | Third-Party Authenticator Apps |
|---|---|---|---|
| Operating system-level authentication that verifies identity with fingerprint, iris, or facial recognition scan, or a PIN or password. | Physical devices that use public-key cryptography. | A smart and simple mobile app that users can easily connect to their Salesforce accounts. | Apps that generate unique, temporary verification codes based on the OATH TOTP algorithm (specified in RFC 6238). |
Security Tier: |
Security Tier:Phishing-resistant | Security Tier:Standard | Security Tier:Standard |
Form Factor: Available via a device's built-in authenticator service (for example, Windows Hello, Touch ID, and Face ID) |
Form Factor: USB, Lightning, and NFC devices that support the WebAuthn and U2F standards |
Form Factor: Mobile app for iOS and Android |
Form Factor: Mobile, desktop, and browser extension apps available for multiple operating systems |
User Experience:
|
User Experience:
|
User Experience:
|
User Experience:
|
Considerations:
|
Considerations:
|
Considerations:
|
Considerations:
|
| Cost: Starts around $25 for biometric peripherals, if needed | Cost: Starts around $20 | Cost: Free | Cost: Free and paid options |
| Learn More | Learn More | Learn More | Learn More |
Notes:
‣ If users don't want to use a mobile authenticator app, consider a TOTP desktop authenticator app or browser extension.
‣ Security keys that use the NFC form factor aren't supported in products built on the Salesforce Platform.
‣ WebAuthn-compatible security keys aren't supported in non-Chromium versions of the Edge browser.
‣ Built-in authenticators are supported in products built on the Salesforce Platform, Heroku, Marketing Cloud Intelligence, MuleSoft Anypoint Platform, and Tableau Cloud.
- Salesforce Authenticator for MFA
The Salesforce Authenticator mobile app is a verification method that can be used as a second factor for multi-factor authentication (MFA) logins. The app is free and simple to use. - Built-In Authenticators (Passkeys) for MFA
Multi-factor authentication (MFA) verification is easy with a built-in authenticator (passkey) service such as Windows Hello, Touch ID, or Face ID. Users can quickly verify their identity with a fingerprint, iris, or facial recognition scan (or in some cases, with a PIN or password that the user sets up in their device's operating system). Built-in authenticators streamline the MFA requirement because they rely on built-in mechanisms rather than users needing a separate authenticator app or physical security key. Built-in authenticators satisfy the phishing-resistant MFA requirement for privileged users. - Security Keys (Passkeys) for MFA
Security keys are physical passkeys. They're small, USB or NFC devices that are easy to use for multi-factor authentication (MFA) logins because there's nothing to install and no codes to enter. This type of method is a great option if users don't have a mobile device or if phones aren't allowed where your users work (such as a PCI-compliant service center). Security keys require a supported browser to act as an intermediary between the key and your Salesforce product. Popular security keys include the YubiKey from Yubico and the Titan Security Key from Google. Security keys satisfy the phishing-resistant MFA requirement for privileged users. - Third-Party Authenticator Apps for MFA
Salesforce multi-factor authentication (MFA) supports the use of third-party authenticator apps that generate time-based one-time password (TOTP) codes. There are many mobile, desktop, and browser extension apps available, including free versions. Some popular options include Google Authenticator, Microsoft Authenticator, Authy, and password managers such as LastPass and 1Password. Third-party authenticator apps are considered standard-strength verification methods, so they can satisfy the MFA requirement for non-privileged users.

