Loading

Phishing Resistant MFA (PR-MFA) for High-Privilege Marketing Cloud Engagement Administrator Accounts

Publiceringsdatum: Aug 12, 2026
Beskrivning

Phishing-Resistant Multi-Factor Authentication (PR-MFA) for high-privilege administrator accounts helps mitigate account takeover and phishing risks. Salesforce strongly recommends adoption to strengthen security ahead of future enforcement.

What’s Changing

Salesforce is enhancing MCE administrator security to protect against phishing and unauthorized account access. Salesforce strongly recommends the adoption of Phishing-Resistant MFA for all high-privilege administrator accounts using username/password login flows.

Starting July 30, 2026, Salesforce will introduce support for WebAuthN platform authenticators. Salesforce strongly encourages administrators to migrate to phishing-resistant options, including certificate-based authentication, platform authenticators (such as Windows Hello, Touch ID, or Passkeys), or FIDO2-compliant hardware security keys.

Why Is Salesforce Making This Change

To enhance the security of high-privilege organizational accounts, Salesforce is introducing phishing-resistant authentication frameworks designed to help defend against advanced identity-compromise risks. This enhancement follows established industry standards, with the goal that administrative permissions are restricted only to verified personnel.

When Phishing-Resistant MFA Enforcement Take Effect

Salesforce plans to technically enforce Phishing-Resistant MFA for MCE admin roles in the future. Additional communications with detailed guidance will be sent to all impacted customers as soon as possible.

Who’s Affected

  • Every highly privileged MCE administrative profile using standard username and password login flows. Administrator roles include:

    • Marketing Cloud Administrator

    • Marketing Cloud Security Administrator

    • Email Studio Administrator

Or 

What to Expect

Salesforce will 

  • automatically detect PR-MFA verifier types

  • support WebAuthN platform authenticators (these are built directly into your device, like Touch ID or Windows Hello), and 

  • provide mandatory enrollment flows through Cloud Preferences.

Administrators who have not yet enrolled a phishing-resistant verifier may authenticate once using their existing method. Following this successful login, they are immediately prompted to enroll in a phishing-resistant authenticator.

Once enforcement is active, administrators logging in via username/password will be required to use PR verifier types. Specific enforcement timelines will be communicated to users in advance. Without proper enrollment at that time, access to MCE may be restricted.

Determining Verification Methods

Marketing Cloud Engagement supports several PR-MFA methods

  • Physical security keys that support WebAuthn or U2F, such as YubiKey from Yubico and Titan Security Key from Google

  • Platform authentication systems such as Touch ID and Face ID on Apple devices, Biometrics on Android devices, and Windows Hello

An Engagement Admin can also send a temporary verification code to any users who forget or lose their verification methods.

Starting July 30, 2026, Salesforce will introduce support for WebAuthN platform authenticators

Lösning

Enrollment

Administrators are directed to "Cloud Preferences" to enroll phishing-resistant authenticators.

Pre-enforcement Workflow

The system currently detects existing MFA verifiers and prompts administrators to enroll in a phishing-resistant authenticator. While enforcement is not yet active, we strongly urge administrators to complete this enrollment now to prepare for future requirements.

Common Questions

Q: What are the WebAuthn-Platform authenticators?
A: These authenticators are built directly into the device you are using. Eg. Apple Touch ID / Face ID, Windows Hello, Android fingerprint scanners.

Q: Is there a way for MCE administrators to check whether the target users in the organization have applied PR-MFA?
A: You can review the multi-factor authentication (MFA) enrollment status of users in your account. Refer Review MFA Enrollment Status for Marketing Cloud Engagement

Q: Will the audit log include information that allows us to confirm whether access was made via PR-MFA?
A: You can review a log of all multi-factor authentication (MFA) registration and verification attempts for your account. Refer View MFA Events in Marketing Cloud Engagement

Change Log

Date

Change

Aug 11, 2026
  • Added permission names that require PRMFA - Administration | Account | Update Account and Security Settings. 

  • Updated the "What to Expect" segment with specific operational actions from Salesforce

  • Updated the PRMFA verification methods in “Determining Verification Methods” section

  • Added FAQs

July 21, 2026Clarified dates for support of WebAuthn-platform authenticators (starts July 30, 2026), and clarified that enforcement of phishing-resistant MFA will be in the future, and communicated in advance specific to each org.
July 20, 2026Initial publication

 

Knowledge-artikelnummer

005389129

 
Laddar
Salesforce Help | Article