Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Exclude Exempt Users from MFA for Salesforce Orgs

Exclude Exempt Users from MFA for Salesforce Orgs

The Waive Multi-Factor Authentication for Exempt Users user permission previously allowed you to exempt specific users from MFA for use cases such as automation. After Salesforce enforces MFA requirements in your org, this permission no longer automatically exempts users from MFA. To restore this exemption for valid use cases, you must contact Salesforce Customer Support.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
User Permissions Needed
To edit profiles and permission sets: Manage Profiles and Permission Sets

After Salesforce enforces MFA in your org, here's what happens to the Waive Multi-Factor Authentication for Exempt Users permission.

  • Users with this permission are no longer exempted. They're prompted to use MFA to log in.
  • The PermissionsBypassMFAForUiLogins API field for the Waive Multi-Factor Authentication for Exempt Users user permission is removed from the PermissionSet and Profile object schema, unless you've reached out to Salesforce Support for an extension to continue using it for valid exempt reasons. When removed, referencing this field by API name causes compilation errors that block package installs or upgrades. Audit your code and metadata and remove all references to this field.

For more information about MFA enforcement, including detailed rollout timelines, see Prepare for MFA Enforcement for All Employee Users and Prepare for Phishing-Resistant MFA Enforcement for Privileged Users including Admins.

If Salesforce Customer Support has granted you access to this permission, you can assign it via a permission set that you apply to specific users. See Create Permission Sets, Enable User Permissions in Permission Sets, and Manage Permission Set Assignments.

If you have custom profiles that are limited to exempt users, you can assign the user permission on the profile. See Profiles for guidance.

Considerations:

This permission overrides these MFA enablement options:

  • Multi-Factor Authentication for User Interface Logins user permission

  • Require multi-factor authentication (MFA) for all direct UI logins to your Salesforce org setting

 
Loading
Salesforce Help | Article