At Salesforce, we take the protection of your data very seriously, and understand that the confidentiality, integrity, and availability of your data is vital to your business. In April, we contacted you to reiterate our commitment to providing the highest level of security for your products with technology like multi-factor authentication (MFA). As your partner in protecting your customer data, we're announcing that, beginning February 1, 2022, Salesforce will begin requiring customers to enable MFA in order to access Salesforce products. MFA is available at no extra cost.
MFA is a secure authentication method that requires users to prove their identity by supplying two or more pieces of evidence (or “factors”) when they log in. One factor is something the user knows, such as their username and password. Other factors are verification methods that the user has in their possession, such as an authenticator app or security key. By tying user access to multiple types of factors, MFA makes it much harder for common threats like phishing attacks and account takeovers to succeed.
The global threat landscape is constantly evolving, and the types of attacks that can cripple a business and exploit consumers are on the rise. As businesses transition to support remote work environments, it’s more important than ever to implement stronger security measures. MFA is one of the easiest, most effective tools for enhancing login security, and safeguarding your business and data against security threats.
All internal users who log in to Salesforce products* (including partner solutions) through the user interface must use MFA. To ensure that MFA is enabled for all your Salesforce users, you can turn it on directly in your Salesforce products or use your SSO provider's MFA service.
* If you have purchased your Salesforce subscriptions from a Salesforce Reseller or OEM Partner, contact your Salesforce Reseller or OEM Partner for more information about the MFA requirement.
The requirement begins on February 1, 2022. We encourage you to begin planning now for this change.
You can enable MFA at any time for these Salesforce products:
We’re hard at work developing MFA for all our other Salesforce products, and are committed to delivering this functionality well before the MFA requirement takes effect so you have time to implement successfully. You will hear from us as this support becomes available in the coming months.
MFA is available at no extra cost. Check out the Multi-Factor Authentication Quick Guide for Admins to learn how to get ready for MFA and roll it out to your users.
We’re committed to helping you succeed with your MFA implementation, and we’ve created extensive resources to assist you in this process. To prepare, check out:
And join us on the trail in the MFA - Getting Started Trailblazer Community.
______
**Correction: February 8, 2021
An email sent on Tuesday, February 2, 2021 misstated MFA requirements for SSO. Beginning February 1, 2022, MFA is required, not just recommended, for internal users who access Salesforce products via SSO.
000392813

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.