Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Disconnect a Security Key from a User’s Account (Salesforce Orgs)

Disconnect a Security Key from a User’s Account (Salesforce Orgs)

Users can register only one WebAuthn (FIDO2) or Universal Second Factor (U2F) security key with their Salesforce account at a time. If a user loses or replaces their security key, you can disconnect the original key from their account. If a user’s security key stops working, reset it by disconnecting the key; then ask the user to restore the key’s connection to their account by re-registering it. It’s also a good security practice to disconnect all of a user’s verification methods if they leave your company.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
User Permissions Needed
To remove a user’s security key registration: Manage Multi-Factor Authentication in User Interface
Important
Important

Salesforce enforces MFA requirements in the summer of 2026. See these articles for more information and detailed rollout timelines.

Note
Note If a user is able to access their account, they can disconnect their security key themselves.
  1. From Setup, use the Quick Find box to find and select Users.
  2. Select the user’s name.
  3. On the user’s detail page, select Remove next to the Security Key (U2F or WebAuthn) field.

After disconnecting the security key, guide the user to re-register it or register their replacement key. Refer them to Register a Security Key as an Identity Verification Method for guidance. Admins can’t register verification methods for users.

 
Loading
Salesforce Help | Article