Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Delegate MFA Management Tasks for Salesforce Orgs

Delegate MFA Management Tasks for Salesforce Orgs

Set up Salesforce admins, and trusted users who aren’t admins, to provide support for your org’s multi-factor authentication (MFA) implementation. For example, suppose you want your company’s Help Desk staff to assist admins by generating temporary verification codes for users who have lost or forgot their MFA verification methods. Assign the Manage Multi-Factor Authentication in User Interface user permission to all admins and anyone else who is supporting MFA, so they can generate codes and help end users with other MFA tasks.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
User Permissions Needed
To edit profiles and permission sets: Manage Profiles and Permission Sets
Important
Important

Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

To assign the permission, select Manage Multi-Factor Authentication in User Interface in a permission set or custom user profile. Users with the permission can perform these tasks.

  • Generate a temporary verification code for a user who can’t access their usual MFA verification method.

  • Disconnect verification methods from a user’s account when the user loses or replaces a device.

  • View user identity verification activity on the Identity Verification History page.

  • View the Identity Verification Methods report by clicking a link on the Identity Verification History page.

  • Create user list views that show which identity verification methods users have registered.

Note
Note Although non-admin users with the permission can view the Identity Verification Methods report, they can’t create custom reports that include data restricted to users with the Manage Users permission.
 
Loading
Salesforce Help | Article