Explains whether it is still necessary to assign the Multi-Factor Authentication for User Interface Logins user permission to users when org-wide Multi-Factor Authentication (MFA) is enabled.
To enable Multi-Factor Authentication (MFA) for the entire organization, follow these steps:
From Setup, in the Quick Find box, enter Identity Verification, and then select Identity Verification.
Select the Require multi-factor authentication (MFA) for all direct UI logins to your Salesforce org checkbox.
Note: This setting applies even if MFA was automatically enabled for your organization.
When org-wide MFA is enabled, MFA is enforced for all internal users in the organization, regardless of whether they have the Multi-Factor Authentication for User Interface Logins user permission assigned.
Therefore, it is not necessary to grant the Multi-Factor Authentication for User Interface Logins permission to users while org-wide MFA is enabled.
Phased Rollout: Assigning the Multi-Factor Authentication for User Interface Logins permission is a method used to roll out MFA to users in phases or pilot groups.
External Users: To enable MFA for external Experience Cloud site users, you must assign the Multi-Factor Authentication for User Interface Logins permission to those specific users. For more details, refer to "Enable MFA for External Experience Cloud Site Users (or Specific Internal Users)" in Salesforce Help.
002623431

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.