Phishing-Resistant Multi-Factor Authentication (PR-MFA) for high-privilege administrator accounts helps mitigate account takeover and phishing risks. Salesforce strongly recommends adoption to strengthen security ahead of future enforcement.
Salesforce is enhancing MCE administrator security to protect against phishing and unauthorized account access. Salesforce strongly recommends the adoption of Phishing-Resistant MFA for all high-privilege administrator accounts using username/password login flows.
Starting July 30, 2026, Salesforce will introduce support for WebAuthN platform authenticators. Salesforce strongly encourages administrators to migrate to phishing-resistant options, including certificate-based authentication, platform authenticators (such as Windows Hello, Touch ID, or Passkeys), or FIDO2-compliant hardware security keys.
To enhance the security of high-privilege organizational accounts, Salesforce is introducing phishing-resistant authentication frameworks designed to help defend against advanced identity-compromise risks. This enhancement follows established industry standards, with the goal that administrative permissions are restricted only to verified personnel.
Salesforce plans to technically enforce Phishing-Resistant MFA for MCE admin roles in the future. Additional communications with detailed guidance will be sent to all impacted customers as soon as possible.
Every highly privileged MCE administrative profile using standard username and password login flows. Administrator roles include:
Marketing Cloud Administrator
Marketing Cloud Security Administrator
Email Studio Administrator
Or
Every user with permissions that include - Administration | Account | Update Account and Security Settings. Refer Permissions for Setting Up Marketing Cloud Engagement
Salesforce will
automatically detect PR-MFA verifier types,
support WebAuthN platform authenticators (these are built directly into your device, like Touch ID or Windows Hello), and
provide mandatory enrollment flows through Cloud Preferences.
Administrators who have not yet enrolled a phishing-resistant verifier may authenticate once using their existing method. Following this successful login, they are immediately prompted to enroll in a phishing-resistant authenticator.
Once enforcement is active, administrators logging in via username/password will be required to use PR verifier types. Specific enforcement timelines will be communicated to users in advance. Without proper enrollment at that time, access to MCE may be restricted.
Marketing Cloud Engagement supports several PR-MFA methods
Physical security keys that support WebAuthn or U2F, such as YubiKey from Yubico and Titan Security Key from Google
Platform authentication systems such as Touch ID and Face ID on Apple devices, Biometrics on Android devices, and Windows Hello
An Engagement Admin can also send a temporary verification code to any users who forget or lose their verification methods.
Starting July 30, 2026, Salesforce will introduce support for WebAuthN platform authenticators
Administrators are directed to "Cloud Preferences" to enroll phishing-resistant authenticators.
The system currently detects existing MFA verifiers and prompts administrators to enroll in a phishing-resistant authenticator. While enforcement is not yet active, we strongly urge administrators to complete this enrollment now to prepare for future requirements.
Q: What are the WebAuthn-Platform authenticators?
A: These authenticators are built directly into the device you are using. Eg. Apple Touch ID / Face ID, Windows Hello, Android fingerprint scanners.
Q: Is there a way for MCE administrators to check whether the target users in the organization have applied PR-MFA?
A: You can review the multi-factor authentication (MFA) enrollment status of users in your account. Refer Review MFA Enrollment Status for Marketing Cloud Engagement
Q: Will the audit log include information that allows us to confirm whether access was made via PR-MFA?
A: You can review a log of all multi-factor authentication (MFA) registration and verification attempts for your account. Refer View MFA Events in Marketing Cloud Engagement
|
Date |
Change |
| Aug 11, 2026 |
|
| July 21, 2026 | Clarified dates for support of WebAuthn-platform authenticators (starts July 30, 2026), and clarified that enforcement of phishing-resistant MFA will be in the future, and communicated in advance specific to each org. |
| July 20, 2026 | Initial publication |
Multi-Factor Authentication for Marketing Cloud Engagement
Multi-Factor Authentication FAQ for Marketing Cloud Engagement
005389129

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.