Phishing-Resistant Multi-Factor Authentication (PR-MFA) for high-privilege administrator accounts helps mitigate account takeover and phishing risks. Salesforce strongly recommends adoption to strengthen security ahead of future enforcement.
Salesforce is enhancing MCE administrator security to protect against phishing and unauthorized account access. Salesforce strongly recommends the adoption of Phishing-Resistant MFA for all high-privilege administrator accounts using username/password login flows.
Starting July 30, 2026, Salesforce will introduce support for WebAuthN platform authenticators. Salesforce strongly encourages administrators to migrate to phishing-resistant options, including certificate-based authentication, platform authenticators (such as Windows Hello, Touch ID, or Passkeys), or FIDO2-compliant hardware security keys.
To enhance the security of high-privilege organizational accounts, Salesforce is introducing phishing-resistant authentication frameworks designed to help defend against advanced identity-compromise risks. This enhancement follows established industry standards, with the goal that administrative permissions are restricted only to verified personnel.
Salesforce plans to technically enforce Phishing-Resistant MFA for MCE admin roles in the future. Additional communications with detailed guidance will be sent to all impacted customers as soon as possible.
Every highly privileged MCE administrative profile using standard username and password login flows. Administrator roles include:
Marketing Cloud Administrator
Marketing Cloud Security Administrator
Email Studio Administrator
Salesforce will automatically detect MFA verifier types, and provide mandatory enrollment flows through Cloud Preferences.
Administrators who have not yet enrolled a phishing-resistant verifier may authenticate once using their existing method. Following this successful login, they are immediately prompted to enroll in a phishing-resistant authenticator.
Once enforcement is active, administrators logging in via username/password will be required to use PR verifier types. Specific enforcement timelines will be communicated to users in advance. Without proper enrollment at that time, access to MCE may be restricted.
Marketing Cloud Engagement currently supports the following Phsihing-Resistant Multi-Factor Authentication (MFA) verification method:
Security keys that support WebAuthN or U2F, such as Yubico’s YubiKey or Google’s Titan Security Key.
An Engagement Admin can also send a temporary verification code to any users who forget or lose their verification methods.
Starting July 30, 2026, Salesforce will introduce support for WebAuthN platform authenticators
Administrators are directed to "Cloud Preferences" to enroll phishing-resistant authenticators.
The system currently detects existing MFA verifiers and prompts administrators to enroll in a phishing-resistant authenticator. While enforcement is not yet active, we strongly urge administrators to complete this enrollment now to prepare for future requirements.
|
Date |
Change |
| July 21, 2026 | Clarified dates for support of WebAuthn-platform authenticators (starts July 30, 2026), and clarified that enforcement of phishing-resistant MFA will be in the future, and communicated in advance specific to each org. |
| July 20, 2026 | Initial publication |
Multi-Factor Authentication FAQ for Marketing Cloud Engagement
005389129

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.