Enable Security Keys for Identity Verification in Salesforce Orgs
Allow your users to verify their identity for multi-factor authentication (MFA) or
device activation with WebAuthn (FIDO2) or Universal Second Factor (U2F) security keys. After
you enable this method, users can register a security key so it’s connected to their Salesforce
account. Security keys are phishing-resistant. Enabling and requiring them is a security best
practice.
Required Editions
Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
User Permissions
Needed
To enable security keys:
Customize Application
AND
Manage Users
In orgs created in Summer ’25 and later, this setting is enabled by default.
From Setup, in the Quick Find box, enter Identity Verification,
and then select Identity Verification.
Select Let users verify their identity with a physical security key (U2F or
WebAuthn).
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.