Require Multi-Factor Authentication for Key Management
Multi-factor authentication (MFA) is a powerful tool for securing access to data and
resources. Salesforce requires the use of MFA for all logins to your org's user interface. In
addition, you can add extra security by also requiring MFA for Shield Platform Encryption key
management tasks like generating, rotating, or uploading key material and
certificates.
Required Editions
Available in: Enterprise, Performance, Unlimited, and
Developer Editions
User Permissions Needed
To assign identity verification for key management tasks:
Manage Encryption Keys
Important Make sure that you provide security administrators a way to get a
time-based, one-time password. This password is their second authentication factor (in addition
to their Salesforce username and password). Otherwise, they can’t complete encryption
key-related tasks.
From Setup, in the Quick Find box, enter Identity Verification, and
then select Identity Verification.
Select Raise session to high-assurance from the Manage Encryption
Keys dropdown.
All admins with the Manage Encryption Keys permission must use an additional
verification method to complete key management tasks through Setup and the API.
Did this article solve your issue?
Let us know so we can improve!
Loading
Salesforce Help | Article
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.