Loading
Prepare for Email to Become the Default Login ExperienceRead More
Intermittent freezing when using using certain browser versionsRead More
Secure Your Salesforce Org
Enable Security Keys for Identity Verification in Salesforce Orgs

Enable Security Keys for Identity Verification in Salesforce Orgs

Security keys are small physical devices, such as YubiKeys or Titan keys, that users can use to set up passkeys for secure multi-factor authentication (MFA). With MFA enforcement, Salesforce automatically enables security keys as an available verification method for all employee users. When MFA is enforced in your org, you can't turn off this setting. If MFA isn't enforced yet in your org, turn on security keys to test them. Security keys satisfy the phishing-resistant MFA requirement for users with privileged permissions. Users can also use security keys to complete other identity verification challenges, such as device activation.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
User Permissions Needed
To turn on security keys:

Customize Application

AND

Manage Users

Important
Important

Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

  1. From Setup, use the Quick Find box to find and select Identity Verification.
  2. Select Let users verify their identity with a physical security key (passkey) such as U2F or WebAuthn.
  3. Save your changes.
 
Loading
Salesforce Help | Article