Loading

Understanding MFA Auto Enablement and Audit Trail Entries in Salesforce

Дата публикации: Aug 18, 2026
Описание

This is a normal process and is expected behavior once the enforced enablement is in effect.

Once Multi-Factor Authentication (MFA) is enabled in the production org, an entry for a non-SSO user appears in the audit trail.

Решение

This section explains why the audit trail logs the first non-SSO user who logs in as the one who enabled MFA, once MFA is automatically enforced after the deferred period.

Why This Happens

  • Deferred Auto Enablement of MFA for Direct UI Logins: Some customers choose to defer the auto enablement of MFA for direct UI logins. This means that even though MFA is required, it isn't enforced immediately for all users.
  • Salesforce's Enforcement of MFA After the Due Date: Once the deferred period expires, Salesforce automatically enforces MFA for direct UI logins. This is a security measure to ensure compliance with Salesforce's MFA requirements.
  • Audit Trail Entry for the First Non-SSO User: After Salesforce enforces MFA enablement, the first non-SSO (Single Sign-On) user who attempts to log in will be recorded in the audit trail as having enabled MFA.
Номер статьи базы знаний

002628753

 
Загрузка
Salesforce Help | Article