PRMFA enforcement applies to privileged users, including:
Standard (non-privileged) users are subject to standard MFA enforcement only and are generally not blocked by PRMFA-specific mobile limitations.
For the full list of privileged user types subject to PRMFA enforcement, see Prepare for Phishing-Resistant MFA Enforcement for Privileged Users including Admins.
The standard Salesforce Mobile App authenticates users through an embedded WebView. This component:
As a result, when PRMFA is enforced and an admin taps "Verify Identity" inside the app, nothing visible happens : no navigation, no prompt, no error. The button initiates a WebAuthn call that the embedded view cannot fulfill.
This is a known product limitation confirmed across iOS and Android.
Expected Behavior After PRMFA EnforcementScenario | Expected Behavior |
| Admin logs in via standard mobile app WebView with PRMFA enforced | Blocked - "Create a Passkey" or passkey prompt shown; tapping Verify Identity does nothing |
| Admin logs in via "Login for Admin" button (app v262.010+) | ✅ Routes through system browser - passkey prompt works |
| Admin logs in via "Login with Email" with Native Browser Auth enabled | ✅ Routes through Safari/Chrome - passkey prompt works |
| Non-admin user logs in via standard mobile app | Not affected by PRMFA; standard MFA applies |
| Mobile SDK ≤ 13.2.0 | Blocked - cannot support PRMFA unless advanced auth pre-configured |
| Mobile SDK 13.2.1+ | ✅ "Login for Admin" menu item enables browser-based phishing-resistant login |
Available from Salesforce Mobile App v262.010+ and Mobile SDK 13.2.1+.
The "Login for Admin" button routes the admin through the system browser (Safari on iOS, Chrome on Android) instead of the embedded WebView, enabling the FIDO2/WebAuthn passkey prompt.
Steps:
Works for all users when the org is configured to use the native browser for authentication.
Prerequisites - enable in Setup:
Steps:
Passkeys are device-bound. A passkey registered on desktop (e.g., via Windows Hello or a cross-device QR code flow) cannot be used on mobile.
To complete PRMFA on mobile, the user must have an iOS- or Android-native biometric passkey registered:
phoneappnotification from ADFS or Entra ID without phishing-resistant Conditional Access), Salesforce will intercept the login and require the admin to register and use a Salesforce-native phishing-resistant method.| Limitation | Detail |
| Embedded WebView does not support FIDO2/WebAuthn | Passkey prompt cannot be surfaced inside the native app - requires browser context |
| Cross-device passkeys (QR code) not supported in mobile app | Must register a device-native biometric passkey via the device's browser |
| Mobile SDK ≤ 13.2.0 cannot support PRMFA | Must upgrade to 13.2.1+ or pre-configure advanced auth |
enableUnifiedPasskeyExperience flag may cause silent failures | When Security Keys are ON and Built-in Authenticators are OFF, passkey flows may time out silently |
AdminPasskeysOptOut extension : if the org cannot surface the passkey prompt and the admin has no other path, verify whether AdminPasskeysOptOut has been granted. If not, consider requesting itenableUnifiedPasskeyExperience flag interaction : go to Setup → Identity Verification and confirm "Built-in Authenticators" is enabled and check the "Security Keys" status. When Security Keys are ON and Built-in Authenticators are OFF, passkey flows may time out silentlyMFA and Phishing-Resistant MFA Post-Enforcement Passkey Prompts and Extension Behavior
Security-Related Product Updates to the Salesforce Platform
Phishing-Resistant MFA Requirement for Privileged Users
Native Browser Authentication for Mobile
Register Built-in Authenticator
Enable Passwordless Login with Passkeys
005390712

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.