You are here:
Salesforce Customer Identity: Passwordless Login Control
This control lets an org replace the generic Salesforce verification screen with a custom-branded page that handles the passwordless login.
Control Name
Passwordless Login
Recommended Configuration
Enable access to Your Custom Identity verification page.
Control Overview
This control lets an org replace the generic Salesforce verification screen with a custom-branded page that handles the passwordless login. Passwordless Authentication allows users to log in using a one-time passcode (OTP) sent via email or SMS, or through a verifiable discovery-based link, rather than a traditional static password. TOTP Authenticator apps and Security Keys (Passkeys) can also be configured.
Security Risk If Not Configured
When not enabled or properly configured, users are forced through standard, unbranded flows that are easier for attackers to mimic in phishing campaigns, leading to users being unable to distinguish your real login process from a fake one.
Threat Scenarios
An attacker launches a credential-harvesting site that looks exactly like the default Salesforce login. Because the company hasn't established a "Custom Identity" visual standard, users enter their sensitive OTPs into the attacker's site without suspicion.
Estimated CVSS Score Range
Critical (9.0–10.0).
Risk Impact Considerations
The failure to provide a consistent, branded verification experience increases the success rate of social engineering attacks, potentially compromising thousands of customer accounts and eroding trust in your digital portal.
Higher Risk When
The risk is higher for high-traffic consumer portals where users are less technically savvy and are more likely to fall for "look-alike" login screens that lack your company's specific security markers.
Low Risk When
Orgs use physical U2F security key in Identity Verification settings to replace vulnerable SMS/email codes where possible. These are more difficult for attackers to phish.
Business and Integration Considerations
Implementing a custom verification page requires front-end development (Visualforce or Lightning) and coordinated testing to ensure that the verification code or link is delivered reliably across different mobile carriers and email providers.
Recommended Remediation
Navigate to Login & Registration in your site's Administration settings, select Passwordless Login, and specify your custom page in the Identity Verification field.
Security Health Review Guidance
Security Health Review identifies custom verification pages as a "Visual Trust Anchor," mandating that the security experience should be indistinguishable from the brand experience to help users instinctively identify fraudulent login attempts.
