When a user accidentally deletes their Multi-Factor Authentication (MFA) authenticator app or changes their smartphone, their MFA registration must be disconnected in Salesforce. This article explains the procedure for a System Administrator to disconnect a user's MFA for Agentforce Sales and Agentforce Service (formerly Sales Cloud and Service Cloud).
Examples of situations that require disconnecting an MFA verification method include:
The user accidentally deleted their MFA authenticator application.
The user removed their Salesforce account from the MFA authenticator application.
The user wants to change their Multi-Factor Authentication (MFA) verification method.
The user changed their mobile device without enabling the backup feature in Salesforce Authenticator.
The user wants to switch to a new mobile device for the authenticator app (e.g., the device was lost or broken).
The user sees the "Verify Your Identity" screen but has forgotten which authenticator application was connected to the account.
Note: Users who are not System Administrators can disconnect MFA for other users if they are assigned the "Manage MFA in User Interface" permission for their Salesforce license. This permission also allows them to generate temporary verification codes, making it a useful backup plan when a System Administrator is unavailable.
(Caution) Be careful not to confuse this with the "Multi-Factor Authentication for User Interface Logins" permission.
This article explains how a System Administrator (or a user with the "Manage MFA in User Interface" permission) disconnects a user's Multi-Factor Authentication (MFA) registration in Salesforce.
If the user is using a Built-in Authenticator, the registration status is shown in the "Built-in Authenticator" section at the bottom of the user's detail record. Click [Remove] to disconnect it.
Recover Access if Your Verification Method Is Replaced, Gets Lost, or Stops Working (Salesforce Orgs)
Delegate MFA Management Tasks for Salesforce Orgs
Generate a Temporary Verification Code for MFA Logins to Salesforce Orgs
Common multi-factor authentication (MFA) troubleshooting
000395007

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.