Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Help Users Register MFA Verification Methods for Direct Login

Help Users Register MFA Verification Methods for Direct Login

Multi-factor authentication (MFA) is required to access production and sandbox orgs. To log in, users must have at least one registered identity verification method that they provide in addition to their username and password. If they haven’t set up a verification method, they’re prompted to register one for MFA when they log in. The registration process connects a verification method to the user’s Salesforce account. Each user must complete this step themselves — Salesforce admins can’t do it for them. But you can head off confusion and support tickets but making sure your users understand what they must do.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
Important
Important

Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

Make sure your users understand the verification method options that are available to them. Then refer them to these help topics for step-by-step guidance as they complete the in-app registration prompts.

It can be an urgent situation if a user isn’t able to log in. With MFA in the equation, remove the risk of access problems by having all users —especially Salesforce admins— register at least two verification methods. This way everyone has a backup available if they lose or forget their primary method. With Salesforce, users can register one method in each of the supported categories. That means they can set up Salesforce Authenticator, a third-party one-time password authenticator app, a physical security key, and a built-in authenticator.

 
Loading
Salesforce Help | Article