Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Disconnect a Passkey from a User’s Account (Salesforce Orgs)

Disconnect a Passkey from a User’s Account (Salesforce Orgs)

If a user loses or replaces the device where they used a passkey (also known as a built-in authenticator), you can disconnect the passkey from their account. If a user’s passkey stops working, reset it by disconnecting the passkey. Then ask the user to re-register their passkey or create a new passkey.It’s also a good security practice to disconnect all of a user’s verification methods if they leave your company.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
User Permissions Needed
To remove a user’s passkey registration: Manage MFA in User Interface
Important
Important

Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

If a user can access their account, they can disconnect their passkey themselves. Refer users to Manage Passkeys and Security Keys.

  1. From Setup, use the Quick Find box to find and select Users.
  2. Select the user’s name.
  3. On the user’s detail page, find the Built-in Authenticators section. Next to the passkey that you want to disconnect, click Del.
    Disconnect a user's built-in authenticator on the user's detail page

After disconnecting the passkey, guide the user to re-register it or create a new passkey. If the user is moving to a replacement device, they must set up the passkey on the device first. Refer them to Create a Passkey for guidance. Admins can’t register verification methods for users.

 
Loading
Salesforce Help | Article