Loading
Salesforce now sends email only from verified domains. Read More
Identify Your Users and Manage Access
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Enable MFA for Your Entire Salesforce Org

          Enable MFA for Your Entire Salesforce Org

          Turn on multi-factor authentication (MFA) for everyone in your org with a single setting. When MFA is enabled, all internal users logging in directly with their username and password must also provide an identity verification method, such as an authenticator app or security key.

          Required Editions

          Available in: both Salesforce Classic and Lightning Experience
          Available in: all editions
          User Permissions Needed
          To modify identity verification settings: Customize Application
          Important
          Important

          As a safeguard against unauthorized account access, customers are contractually required to use MFA when logging in to Salesforce. To help users satisfy this requirement, the setting discussed in this topic is automatically enabled for production orgs. For full details about the MFA requirement, see the Salesforce Multi-Factor Authentication FAQ.

          Before you begin:

          To enable MFA for all internal users in your org:

          1. From Setup, in the Quick Find box, enter Identity, and then select Identity Verification.
          2. Select Require multi-factor authentication (MFA) for all direct UI logins to your Salesforce org.
          Note
          Note Ensure that admins and other privileged users are able to perform actions that require a high assurance-level of security. On the Session Settings page in Setup, make sure Multi-Factor Authentication is in the High Assurance column.

          Considerations:

          • Users who have been assigned the Multi-Factor Authentication for User Interface Logins user permission experience no change when this org setting is enabled.

          • The Waive Multi-Factor Authentication for Exempt Users user permission overrides this setting.

          • If the Require multi-factor authentication (MFA) for all direct UI logins to your Salesforce org setting is disabled in a production org, all Salesforce admins see a warning prompt when working in Setup. These recurring prompts advise that the org is out of compliance with the MFA requirement and provide guidance on how to re-enable MFA.
           
          Loading
          Salesforce Help | Article