Loading

Device Activation for SSO Logins Resources

Julkaisupäivä: Jun 26, 2026
Kuvaus

This article provides resources for Salesforce administrators and users managing device activation requirements for Single Sign-On (SSO) logins. When Salesforce enforces Multi-Factor Authentication (MFA) with an external Identity Provider (IdP), users connecting via SSO must activate their device before they can log in. This requirement applies to orgs using Okta, Microsoft Azure Active Directory, Cisco Duo, and other external IdP configurations.
Use the resources below to understand extension requests, compliance requirements, and IdP-specific guidance.

Ratkaisu

Request a 30-Day Extension

If your organization needs additional time to comply with the SSO device activation requirement, you can request a temporary 30-day extension. Submit your request through the standard Salesforce support process and include your org ID and the reason for the delay.

Comply with SSO MFA Requirements

To comply with the Salesforce MFA requirement when using an external IdP for SSO, ensure that your IdP is configured to satisfy the MFA requirement at the IdP level. Salesforce recognizes MFA performed by a trusted SSO IdP as satisfying the platform requirement, so no additional in-app MFA step is required for SSO users.
Steps to verify compliance:

  1. Confirm that your IdP enforces MFA during the SSO login flow.
  2. Review the Salesforce SSO and MFA documentation to verify your IdP is on the supported list.
  3. If your IdP is not on the list, configure Salesforce's built-in MFA for those users.

External IdP Resources

The following identity providers have specific guidance for device activation and MFA:

  • Okta: Review the Okta SSO Device Activation FAQ for configuration steps specific to Salesforce SSO integrations.
  • Microsoft Azure Active Directory: Refer to the Azure AD Conditional Access documentation to ensure MFA is enforced before the SAML assertion is issued to Salesforce.
  • Cisco Duo: Duo Security can be configured as an IdP or as an MFA layer on top of an existing IdP. Ensure Duo prompts users before the Salesforce SAML response is generated.


Lisäresurssit
Knowledge-artikkelin numero

005321709

 
Ladataan
Salesforce Help | Article