Turn on multi-factor authentication (MFA) for everyone in your org with a single
setting. When MFA is enabled, all internal users logging in directly with their username and
password must also provide an identity verification method, such as an authenticator app or
security key.
Required Editions
Available in: both Salesforce Classic and Lightning Experience
After MFA is enforced, this setting is turned on and can't be disabled.
To turn on MFA for all internal users in your org:
From Setup, in the Quick Find box, enter Identity, and
then select Identity Verification.
Select Require multi-factor authentication (MFA) for all direct UI logins to
your Salesforce org.
Note Make sure that admins and other privileged users are able to
perform actions that require a high assurance-level of security. On the Session Settings
page in Setup, make sure multi-factor authentication is in the High Assurance column.
Considerations:
Before MFA enforcement, you can use the Multi-Factor Authentication for User Interface
Logins permission (API name: PermissionsForceTwoFactor) to require
MFA for specific users instead of turning it on for your whole org. However, the
org-wide setting enforces MFA for all direct UI logins, even if users don't have the
individual permission. When Salesforce enables the org-wide permission with MFA
enforcement, users must use MFA even if they don't have this permission.
This setting applies only to direct UI logins with a username and password. It doesn't
affect logins through single sign-on (SSO). For MFA requirements when using SSO, including
how admin and privileged user requirements interact with the AMR (Authentication Method
Reference) attribute, see Use Salesforce MFA for SSO (Salesforce Orgs).
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.