Loading

Phishing Resistant MFA (PR-MFA) for High-Privilege Marketing Cloud Engagement Administrator Accounts

Date de publication: Jul 21, 2026
Description

Phishing-Resistant Multi-Factor Authentication (PR-MFA) for high-privilege administrator accounts helps mitigate account takeover and phishing risks. Salesforce strongly recommends adoption to strengthen security ahead of future enforcement.

What’s Changing

Salesforce is enhancing MCE administrator security to protect against phishing and unauthorized account access. Salesforce strongly recommends the adoption of Phishing-Resistant MFA for all high-privilege administrator accounts using username/password login flows.

Starting July 30, 2026, Salesforce will introduce support for WebAuthN platform authenticators. Salesforce strongly encourages administrators to migrate to phishing-resistant options, including certificate-based authentication, platform authenticators (such as Windows Hello, Touch ID, or Passkeys), or FIDO2-compliant hardware security keys.

Why Is Salesforce Making This Change

To enhance the security of high-privilege organizational accounts, Salesforce is introducing phishing-resistant authentication frameworks designed to help defend against advanced identity-compromise risks. This enhancement follows established industry standards, with the goal that administrative permissions are restricted only to verified personnel.

When Phishing-Resistant MFA Enforcement Take Effect

Salesforce plans to technically enforce Phishing-Resistant MFA for MCE admin roles in the future. Additional communications with detailed guidance will be sent to all impacted customers as soon as possible.

Who’s Affected

Every highly privileged MCE administrative profile using standard username and password login flows. Administrator roles include:

  • Marketing Cloud Administrator

  • Marketing Cloud Security Administrator

  • Email Studio Administrator

What to Expect

Salesforce will automatically detect MFA verifier types, and provide mandatory enrollment flows through Cloud Preferences.

Administrators who have not yet enrolled a phishing-resistant verifier may authenticate once using their existing method. Following this successful login, they are immediately prompted to enroll in a phishing-resistant authenticator.

Once enforcement is active, administrators logging in via username/password will be required to use PR verifier types. Specific enforcement timelines will be communicated to users in advance. Without proper enrollment at that time, access to MCE may be restricted.

Determining Verification Methods

Marketing Cloud Engagement currently supports the following Phsihing-Resistant Multi-Factor Authentication (MFA) verification method:

An Engagement Admin can also send a temporary verification code to any users who forget or lose their verification methods.

Starting July 30, 2026, Salesforce will introduce support for WebAuthN platform authenticators

Enrollment

Administrators are directed to "Cloud Preferences" to enroll phishing-resistant authenticators.

Pre-enforcement Workflow

The system currently detects existing MFA verifiers and prompts administrators to enroll in a phishing-resistant authenticator. While enforcement is not yet active, we strongly urge administrators to complete this enrollment now to prepare for future requirements.

Résolution

Change Log

Date

Change

July 21, 2026Clarified dates for support of WebAuthn-platform authenticators (starts July 30, 2026), and clarified that enforcement of phishing-resistant MFA will be in the future, and communicated in advance specific to each org.
July 20, 2026Initial publication

 

Numéro d’article de la base de connaissances

005389129

 
Chargement
Salesforce Help | Article