This article helps you troubleshoot common issues with Salesforce Authenticator, the mobile app used for multi-factor authentication (MFA) with your Salesforce account. Use the sections below to find fixes for login problems, location-based automation issues, slow approval responses, and new phone setups.
This article answers the question: what should you do when Salesforce Authenticator isn't working as expected, whether you can't log in, the app won't remember your trusted location, approvals are slow to arrive, or you've switched to a new phone? Use the sections below to find the fix that matches your situation.
Contact your Salesforce administrator. The Salesforce administrator is someone at your company who has additional permissions and performs configuration tasks for your Salesforce instance.
If they can't help you, contact Salesforce support.
See Troubleshoot Login Issues for more help with Salesforce logins.
Ensure Location Services is set to "Always" and Background App Refresh is enabled in iOS, or enable Improve Location Accuracy in Location Services in Android. See Automate Multi-Factor Authentication with Salesforce Authenticator for more help.
Ask your Salesforce administrator if automation is configured to only work on certain networks.
Remove all previously trusted locations, and re-add them.
Confirm that "Let Salesforce Authenticator automatically verify identities using geolocation" is enabled, and "Let Salesforce Authenticator automatically verify identities based on trusted IP addresses only" is disabled in Setup under Identity Verification.
Note that the following criteria must be met for auto-approval to take place:
For more troubleshooting tips, see Optimize and Troubleshoot Automation in Salesforce Authenticator.
Check your phone's network connection. Slow Wi-Fi or cellular connections will affect the speed of push notifications.
On the Salesforce Check Your Mobile Device page, tap "Having Trouble?" and then tap "Use a Different Verification Method." Enter the 6-digit code from Salesforce Authenticator. This works even when your phone is offline.
If you previously backed up your connected accounts, you can restore your configuration. See Restore Connected Accounts in the Salesforce Authenticator Mobile App to learn how.
If necessary, remove the account from Salesforce Authenticator, re-configure Salesforce Authenticator, and then (optionally) turn on backup. See Connect Your Salesforce Account to Salesforce Authenticator for setup steps.
If your phone is lost or stolen, or you have a new phone and the previous one is unavailable, follow the steps in the "Can't Log In and Need Immediate Assistance" section above. Your Salesforce administrator can remove the connection from the inaccessible phone. Contact Salesforce Support if your administrator can't assist.
Salesforce Authenticator connections are paired with devices, not phone numbers. When you change devices, the new installation doesn't know about your existing connection, so you're shown a two-word phrase to set up a new one. Since your old device still has an active connection with Salesforce, we ask for that phrase to confirm the switch — this is why a Salesforce administrator should remove the old connection first.
In the reverse scenario, if Salesforce asks for a two-word phrase, it usually means the Authenticator app still has a connection to an old account, a sandbox account, or a different account, and the account you're signing in to doesn't yet have a connection. In that case, the connection needs to be added.
See also:
Get help with Salesforce Authenticator. See also: How to Use Salesforce Authenticator for MFA Logins
Watch the video, How MFA Works to Protect Account Access
Third-Party Authenticator Apps
Troubleshoot Multi Factor Authentication issues
000380378

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.