Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Verification Method Selection During MFA Registration

Verification Method Selection During MFA Registration

With MFA enforcement, Salesforce prompts employee users who don't have a registered verification method to set up passkeys, also known as built-in authenticators. Salesforce requires passkeys for direct login for users with privileged permissions. Users who don't have these privileged permissions (non-privileged users) can choose to set up another verification method for direct login, such as Salesforce Authenticator. But passkeys are still the first option that all users see in the MFA registration flow, regardless of their permissions.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
User Permissions Needed
To modify identity verification settings: Customize Application
Important
Important

Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

Changes to Identity Verification Settings with MFA Enforcement

To enable passkey-first MFA registration, Salesforce automatically updates these settings on the Identity Verification page in Setup. You can't change these settings after MFA enforcement.

  • Let users verify their identity with a built-in authenticator (passkey) such as Touch ID or Windows Hello—automatically enabled, so that users can set up passkeys.
  • Let users verify their identity with a physical security key (passkey) such as U2F or WebAuthn—automatically enabled, so that users can set up security keys, which are physical devices that store passkeys.
  • Show all permitted verification method options for MFA registration—automatically disabled, so that MFA registration begins with passkeys instead of showing users all verification methods.

How These Changes Affect Privileged Users

A privileged user has the System Administrator profile or the Modify All Data, View All Data, Customize Application, or Author Apex user permissions. Salesforce requires these users to use phishing-resistant MFA. If a user doesn't meet the requirement, they see a prompt to create a passkey for phishing-resistant MFA when they log in. They can't select another verification method.

Create a Passkey prompt for privileged users

How These Changes Affect Non-Privileged Users

A non-privileged employee user is any internal user who doesn't have privileged permissions. Most employee users are non-privileged. Non-privileged users can satisfy the MFA requirement with either phishing-resistant or standard verification methods. Passkeys are phishing-resistant, while standard-strength verification methods include Salesforce Authenticator and one-time password apps, such as Google Authenticator.

With passkey-first MFA registration, non-privileged users see a prompt to set up a passkey after they enter their username and password. This MFA registration experience applies even though these users have other MFA options besides passkeys.

Create a Passkey prompt for non-privileged users

Non-privileged users can either create a passkey or click Choose Another Verification Method, which shows them options to set up other verification methods.

Choose a Verification Method page with options to set up a passkey, Salesforce Authenticator, or a one-time password app
 
Loading
Salesforce Help | Article