The MFA requirement for MCE SSO users is designed to mitigate risks associated with phishing and account takeovers for MCE users. By implementing Multi-Factor Authentication (MFA), the protection of user accounts that rely on SSO authentication is enhanced.
Since February 1, 2022, Salesforce has required multi-factor authentication (MFA) as the baseline authentication requirement for all employee users accessing MCE environments via Single Sign-On (SSO). To ensure technical compliance ahead of the enforcement deadline, we are instituting validation of standards-based federation assurance signals — specifically Authentication Method Reference (AMR) and Authentication Context Class Reference (ACR) — passed to us by your Identity Provider during the authentication process.
Salesforce aims to ensure all MCE user sessions are protected by MFA, regardless of the login method (Salesforce-managed vs. Federated SSO). Currently, MCE cannot independently verify if MFA was enforced for users logging in via Federated SSO, as authentication happens externally. The current federation assurance visibility across these environments is incomplete. Without these standards-based signals, Salesforce cannot confirm that second-factor protection is in place, thus creating a security gap. This initiative ensures that either the external IdP confirms MFA is active, or the user is guided to enroll in Salesforce-managed MFA.
Multi-Factor Authentication (MFA) is one of the most effective defenses against common, high-impact security threats. By enforcing MFA for MCE SSO users, this requirement mitigates:
Credential-Based Attacks: Preventing unauthorized access even if SSO credentials are compromised.
Phishing: Neutralizing the effectiveness of stolen passwords by requiring a second, phishing-resistant factor.
Session Hijacking: Reducing the impact of credential reuse by ensuring MFA signals are verified at the moment of authentication.
The enforcement starts January 29, 2027 and will be staggered over 5 days. We recommend that users test their configurations well before the enforcement date.
The scope of this mandate includes all MCE users accessing environments via Federated SSO, excluding those who satisfy the following conditions:
Every highly privileged MCE administrative profile using standard username and password login flows. Administrator roles include:
Marketing Cloud Administrator
Marketing Cloud Security Administrator
Email Studio Administrator
and,
Every user with permissions that include - Administration | Account | Update Account and Security Settings. Refer Permissions for Setting Up Marketing Cloud Engagement
Note: Users with these privileges are subject to stricter Phishing-Resistant MFA requirements.
If you already use compliant MFA: If your enterprise IdP is configured to emit valid federation assurance signals (AMR/ACR), you will be considered compliant. You can continue using your SSO as your preferred authentication model without additional Salesforce-side enrollment.
If you are currently non-compliant: You may be required to take action, such as:
Updating your IdP configuration to map and transmit the correct federation assurance values.
Enabling supported MFA methods at the IdP level.
Enrolling users in Salesforce-managed MFA if your IdP cannot be configured to meet the standards.
To prepare for this transition, users need to make sure their Identity Provider (IdP) is correctly set up to transmit their MFA status. Specifically, customers must activate MFA for SSO logins within their respective IdP, and then verify that the IdP is properly configured to pass along this MFA status utilizing ACR/AMR.
Verify Your Current SSO Compliance: You have two primary paths for SSO: either update your Identity Provider (IdP) to require standard MFA authentication and transmit the necessary AMR/ACR signals, or you may enable Salesforce MFA for your SSO logins. If leveraging your IdP’s MFA service, confirm that the SAML response includes the required AMR/ACR signals.
Align with Standards: Customers should map acceptable MFA assurance values within their IdP to meet standards-compliant signaling requirements.
Validate Posture: Review current SSO authentication flows to determine if your IdP is already transmitting valid federation assurance signals that demonstrate MFA usage.
Monitor Communications: Watch for notifications regarding missing or weak federation assurance signals from Salesforce, as these communications will provide guidance on necessary configuration updates.
If your IdP is already sending strong authentication signals and is compliant with Salesforce standards, you should be able to continue using your preferred SSO authentication model without additional Salesforce-managed MFA enrollment.
Enroll in Salesforce MFA: To ensure uninterrupted access if your IdP cannot transmit the required signals, you can proactively enroll users in Salesforce-managed MFA as a seamless secondary verification method."
Maintain Salesforce MFA Verifier: Users may be required to register and maintain a Salesforce MFA verifier alongside their enterprise IdP authentication.
How are API logins affected?
This change targets UI-based employee logins only
What happens if my IdP does not send valid MFA signals?
If your IdP emits weak, incomplete, or missing signals, you will be guided to either correct your IdP configuration to meet standards or, if necessary, enroll in Salesforce-managed MFA.
We already enforce MFA through our SSO provider (e.g., Okta, ADFS, Entra). Do we still need to configure Salesforce MFA?
SSO logins can satisfy the Salesforce MFA requirement — but only if your identity provider (IdP) sends valid AMR (Authentication Methods Reference) or ACR (Authentication Context Class Reference) signals proving MFA was used. By default, all SSO logins are treated as having no MFA until a recognized phishing-resistant MFA or standard MFA signal is received. If Salesforce cannot detect a valid signal from your IdP, users will be prompted to enroll in Salesforce MFA
|
Date |
Change |
| August 11, 2026 | Initial publication |
005389130

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.