Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Enable Passkeys for Identity Verification in Salesforce Orgs

Enable Passkeys for Identity Verification in Salesforce Orgs

With passkeys, users can log in and complete multi-factor authentication (MFA) with Touch ID or Face ID, Windows Hello, a device password, or password managers. With MFA enforcement, Salesforce automatically enables passkeys (also known as built-in authenticators) as an available verification method for all employee users. When MFA is enforced in your org, you can't turn off this setting. If MFA isn't enforced yet in your org, turn on passkeys to test them. Passkeys satisfy the phishing-resistant MFA requirement for privileged users. Users can also use security keys to complete other identity verification challenges, such as device activation.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
User Permissions Needed
To turn on passkeys:

Customize Application

AND

Manage Users

Important
Important

Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

  1. From Setup, use the Quick Find box to find and select Identity Verification.
  2. Select Let users verify their identity with a built-in authenticator (passkey) such as Touch ID or Windows Hello.
  3. Save the change.
 
Loading
Salesforce Help | Article