Multi-factor authentication (MFA) is required for most Salesforce users, but several user types, login types, and org types are excluded. Per the Salesforce Multi-Factor Authentication FAQ, the exclusions include:
For products built on the Salesforce Platform, MFA isn't required for your company's Experience Cloud sites, employee communities, help portals, or e-commerce sites/storefronts. You don't have to enable MFA for external users who access these sites. You can identify external users by these types of licenses:
For Tableau Online, MFA isn't required for Tableau Online external users who consume visualizations in embedded contexts or for external users of a customer's Tableau Online site.
Whether MFA is required for a sandbox environment depends on the Salesforce product.
For products built on the Salesforce Platform: Sandboxes are temporarily excluded from the MFA requirement. The requirement will apply in the future, after we’ve released features that make it easier to manage MFA in these environments. Even though MFA isn’t required for sandboxes at this time, we strongly recommend using MFA for these environments if they include any intellectual property, customer data, or other Salesforce production data.
For B2C Commerce and Marketing Cloud Intelligence: MFA is required for sandbox environments. These environments will be affected when MFA is enforced for B2C Commerce and Marketing Cloud Intelligence customers.
For products, such as Marketing Cloud Engagement, that don’t have formal sandbox environments: Even if you have tenants, orgs, or instances that are used solely for testing purposes, MFA is required for these environments.
000389309

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.