Loading
Prepare for Email to Become the Default Login ExperienceRead More
Intermittent freezing when using using certain browser versionsRead More
Secure Your Salesforce Org
Review Multi-Factor Authentication Controls

Review Multi-Factor Authentication Controls

Multi-factor authentication (MFA) is a secure authentication method that requires users to verify their identity with a second piece of evidence (or factor) in addition to their password.

To protect users from security threats like phishing, credential stuffing, and account takeovers, Salesforce requires MFA for all direct and single sign-on (single sign-on) logins to production and sandbox orgs. As security threats grow more common, it's important to implement strong measures to protect your Salesforce data, your business, and your customers. Usernames and passwords alone are no longer sufficient for guarding against unauthorized account access. By requiring multiple forms of verification to confirm a user's identity, MFA is one of the most straightforward and powerful methods for strengthening login security.

Salesforce automatically enforces MFA. For direct logins, your users must register a verification method. See Register an Identity Verification Method for Salesforce Orgs.

For single sign-on (SSO), you can meet the requirement by using your identity provider's MFA service. To do so, your provider must comply with Salesforce security standards. For more information, see Set Up MFA with an SSO Identity Provider. If you don't use your identity provider's MFA service, Salesforce requires users to register an identity verification to log in.

Security Health Review uses configuration signals to assess your MFA implementation against Salesforce best practices, identifying high-risk security and business gaps. To keep your MFA settings secure, run Health Check periodically.

 
Loading
Salesforce Help | Article