Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Troubleshoot Passkey Issues

Troubleshoot Passkey Issues

When employee users log in and register for multi-factor authentication (MFA), passkeys are the default option. Identify and resolve issues with passkey prompts, setup, login, and more.

  • Access Your Account When You Can’t Use a Passkey
    Regain access to Salesforce if passkey issues prevent you from logging in.
  • Recognize Passkey Creation Prompt Behavior
    Users see prompts to create a passkey in several situations, including after a sandbox refresh. The “Waive Multi-Factor Authentication for Exempt Users” permission applies only to customers with an active temporary extension for multi-factor authentication (MFA) enforcement.
  • Troubleshoot Issues with Passkey Prompts and Single Sign-On
    A user logs in through a single sign-on (SSO) identity provider, such as Okta or Microsoft Entra ID, and completes multi-factor authentication. Before the user can access Salesforce, another prompt asks them to create a passkey. Troubleshoot the authentication signals that cause this issue. This guide includes troubleshooting steps for both Security Assertion Markup Language (SAML) and OpenID Connect.
  • Troubleshoot When a User Can't Create a Passkey
    Help users resolve passkey registration issues with their browser, device, or operating system after they select Create Passkey.
  • Resolve Issues with Passkeys Across Devices
    Each passkey is either device-bound or available for cross-device use. If you have a device-bound passkey and use multiple devices to log in, you have two options. Disconnect the passkey and set up a cross-device passkey, or set up a separate device-bound passkey on each device.
  • Passkey Troubleshooting in the Salesforce App
    Resolve issues with passkeys in the Salesforce app and apps that use Salesforce Mobile SDK.
  • Set Up Passkeys for Partner Admin Shared Logins
    To set up passkeys across devices for Partner Admin Shared Logins, use a synced passkey stored in a password manager. All Partner Admins can use the synced passkey when they’re logged in to the password manager on their devices.
  • Experience Cloud Passkey Prompts
    When an internal user accesses an Experience Cloud site, multi-factor authentication (MFA) is always required. Salesforce doesn't require MFA for external users to access Experience Cloud sites, but you can choose to enable it. Both internal and external users can see prompts to set up a passkey when they log in to an Experience Cloud site, but the prompts are slightly different.
  • Troubleshoot Integration or API User Account Login Issues After MFA Enforcement
    An integration or API user account can experience login issues after MFA enforcement. Although API logins don’t require MFA, some integrations use authentication methods that complete a user interface (UI) login, which requires MFA.
 
Loading
Salesforce Help | Article