Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Disconnect Identity Verification Methods that are Lost, Replaced, or Not Working (Salesforce Orgs)

Disconnect Identity Verification Methods that are Lost, Replaced, or Not Working (Salesforce Orgs)

When addressing multi-factor authentication (MFA) access issues, there are situations where a Salesforce admin must disconnect a user’s current verification method from their Salesforce account. This step is necessary if a user has lost their method, or has acquired a replacement method that they want to use instead of their current one. If a user’s method stops working, disconnecting it allows the user to re-register the method and restore its connection to their account. It’s also a good practice to disconnect all of a user’s verification methods if they leave your company.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
Important
Important

Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

  • Disconnect Salesforce Authenticator from a User’s Account (Salesforce Orgs)
    Only one Salesforce Authenticator mobile app can be connected to a user’s account at a time. If a user loses or replaces the mobile device where Salesforce Authenticator was installed, you can disconnect the app from their account. If a user’s app stops working, reset it by disconnecting the app; then ask the user to restore the app’s connection to their account by re-registering it. It’s also a good security practice to disconnect all of a user’s verification methods if they leave your company.
  • Disconnect a Passkey from a User’s Account (Salesforce Orgs)
    If a user loses or replaces the device where they used a passkey (also known as a built-in authenticator), you can disconnect the passkey from their account. If a user’s passkey stops working, reset it by disconnecting the passkey. Then ask the user to re-register their passkey or create a new passkey.It’s also a good security practice to disconnect all of a user’s verification methods if they leave your company.
  • Disconnect a Security Key from a User’s Account (Salesforce Orgs)
    Users can register only one WebAuthn (FIDO2) or Universal Second Factor (U2F) security key with their Salesforce account at a time. If a user loses or replaces their security key, you can disconnect the original key from their account. If a user’s security key stops working, reset it by disconnecting the key; then ask the user to restore the key’s connection to their account by re-registering it. It’s also a good security practice to disconnect all of a user’s verification methods if they leave your company.
  • Disconnect a Third-Party Authenticator App from a User’s Account (Salesforce Orgs)
    Only one third-party authenticator app that generates time-based one-time passwords (TOTP) codes can be connected to a user’s account at a time. If a user loses or replaces the device where their TOTP authenticator app was installed, you can disconnect the app from their account. If a user’s app stops working, reset it by disconnecting the app; then ask the user to restore the app’s connection to their account by re-registering it. It’s also a good security practice to disconnect all of a user’s verification methods if they leave your company.
 
Loading
Salesforce Help | Article