Loading

MFA Requirement for Marketing Cloud Engagement (MCE) SSO Users

Udgivelsesdato: Aug 11, 2026
Beskrivelse

The MFA requirement for MCE SSO users is designed to mitigate risks associated with phishing and account takeovers for MCE users. By implementing Multi-Factor Authentication (MFA), the protection of user accounts that rely on SSO authentication is enhanced.

What’s Changing

Since February 1, 2022, Salesforce has required multi-factor authentication (MFA) as the baseline authentication requirement for all employee users accessing MCE environments via Single Sign-On (SSO). To ensure technical compliance ahead of the enforcement deadline, we are instituting validation of standards-based federation assurance signals — specifically Authentication Method Reference (AMR) and Authentication Context Class Reference (ACR) — passed to us by your Identity Provider during the authentication process.

Why Is Salesforce Making This Change

Salesforce aims to ensure all MCE user sessions are protected by MFA, regardless of the login method (Salesforce-managed vs. Federated SSO). Currently, MCE cannot independently verify if MFA was enforced for users logging in via Federated SSO, as authentication happens externally. The current federation assurance visibility across these environments is incomplete. Without these standards-based signals, Salesforce cannot confirm that second-factor protection is in place, thus creating a security gap. This initiative ensures that either the external IdP confirms MFA is active, or the user is guided to enroll in Salesforce-managed MFA.

Why This Matters (Threats Mitigated)

Multi-Factor Authentication (MFA) is one of the most effective defenses against common, high-impact security threats. By enforcing MFA for MCE SSO users, this requirement mitigates:

  • Credential-Based Attacks: Preventing unauthorized access even if SSO credentials are compromised.

  • Phishing: Neutralizing the effectiveness of stolen passwords by requiring a second, phishing-resistant factor.

  • Session Hijacking: Reducing the impact of credential reuse by ensuring MFA signals are verified at the moment of authentication.

When Does This Change Take Effect

The enforcement starts January 29, 2027 and will be staggered over 5 days.  We recommend that users test their configurations well before the enforcement date.

Who’s Affected

The scope of this mandate includes all MCE users accessing environments via Federated SSO, excluding those who satisfy the following conditions:

  • Every highly privileged MCE administrative profile using standard username and password login flows. Administrator roles include:

    • Marketing Cloud Administrator

    • Marketing Cloud Security Administrator

    • Email Studio Administrator

and,

Note: Users with these privileges are subject to stricter Phishing-Resistant MFA requirements.

What to Expect

If you already use compliant MFA: If your enterprise IdP is configured to emit valid federation assurance signals (AMR/ACR), you will be considered compliant. You can continue using your SSO as your preferred authentication model without additional Salesforce-side enrollment.

If you are currently non-compliant: You may be required to take action, such as:

  • Updating your IdP configuration to map and transmit the correct federation assurance values.

  • Enabling supported MFA methods at the IdP level.

  • Enrolling users in Salesforce-managed MFA if your IdP cannot be configured to meet the standards.

Løsning

Before Enforcement: How to Prepare

To prepare for this transition, users need to make sure their Identity Provider (IdP) is correctly set up to transmit their MFA status. Specifically, customers must activate MFA for SSO logins within their respective IdP, and then verify that the IdP is properly configured to pass along this MFA status utilizing ACR/AMR.

  1. Verify Your Current SSO Compliance: You have two primary paths for SSO: either update your Identity Provider (IdP) to require standard MFA authentication and transmit the necessary AMR/ACR signals, or you may enable Salesforce MFA for your SSO logins. If leveraging your IdP’s MFA service, confirm that the SAML response includes the required AMR/ACR signals.

  2. Align with Standards: Customers should map acceptable MFA assurance values within their IdP to meet standards-compliant signaling requirements.

  3. Validate Posture: Review current SSO authentication flows to determine if your IdP is already transmitting valid federation assurance signals that demonstrate MFA usage.

  4. Monitor Communications: Watch for notifications regarding missing or weak federation assurance signals from Salesforce, as these communications will provide guidance on necessary configuration updates.

After Enforcement: Resolve Errors

If your IdP is already sending strong authentication signals and is compliant with Salesforce standards, you should be able to continue using your preferred SSO authentication model without additional Salesforce-managed MFA enrollment.

  • Enroll in Salesforce MFA: To ensure uninterrupted access if your IdP cannot transmit the required signals, you can proactively enroll users in Salesforce-managed MFA as a seamless secondary verification method."

  • Maintain Salesforce MFA Verifier: Users may be required to register and maintain a Salesforce MFA verifier alongside their enterprise IdP authentication.

Common Questions

How are API logins affected?

This change targets UI-based employee logins only

 

What happens if my IdP does not send valid MFA signals?

If your IdP emits weak, incomplete, or missing signals, you will be guided to either correct your IdP configuration to meet standards or, if necessary, enroll in Salesforce-managed MFA.

 

We already enforce MFA through our SSO provider (e.g., Okta, ADFS, Entra). Do we still need to configure Salesforce MFA?

SSO logins can satisfy the Salesforce MFA requirement — but only if your identity provider (IdP) sends valid AMR (Authentication Methods Reference) or ACR (Authentication Context Class Reference) signals proving MFA was used. By default, all SSO logins are treated as having no MFA until a recognized phishing-resistant MFA or standard MFA signal is received. If Salesforce cannot detect a valid signal from your IdP, users will be prompted to enroll in Salesforce MFA

Change Log

Date

Change

August 11, 2026Initial publication

 

Vidensartikelnummer

005389130

 
Indlæser
Salesforce Help | Article