Loading
시스템 관리자에 대한 피싱 방지 MFA 및 전 직원사용자 MFA 적용 안내 더 많이 읽기

PRMFA with Salesforce Mobile App Logins

게시 일자: Aug 7, 2026
상세 설명

Who Is Affected?

PRMFA enforcement applies to privileged users, including:

  • System Administrators
  • Users with administrative or elevated permissions

Standard (non-privileged) users are subject to standard MFA enforcement only and are generally not blocked by PRMFA-specific mobile limitations.

For the full list of privileged user types subject to PRMFA enforcement, see Prepare for Phishing-Resistant MFA Enforcement for Privileged Users including Admins.

Why PRMFA Affects Mobile App Logins

The standard Salesforce Mobile App authenticates users through an embedded WebView. This component:

  • Cannot natively invoke the FIDO2/WebAuthn passkey authenticator
  • Cannot present a Touch ID / Face ID passkey prompt inline
  • Cannot fulfill the WebAuthn credential challenge required by PRMFA

As a result, when PRMFA is enforced and an admin taps "Verify Identity" inside the app, nothing visible happens : no navigation, no prompt, no error. The button initiates a WebAuthn call that the embedded view cannot fulfill.
This is a known product limitation confirmed across iOS and Android.

Expected Behavior After PRMFA Enforcement

Scenario
Expected Behavior
Admin logs in via standard mobile app WebView with PRMFA enforcedBlocked - "Create a Passkey" or passkey prompt shown; tapping Verify Identity does nothing
Admin logs in via "Login for Admin" button (app v262.010+)✅ Routes through system browser - passkey prompt works
Admin logs in via "Login with Email" with Native Browser Auth enabled✅ Routes through Safari/Chrome - passkey prompt works
Non-admin user logs in via standard mobile appNot affected by PRMFA; standard MFA applies
Mobile SDK ≤ 13.2.0Blocked - cannot support PRMFA unless advanced auth pre-configured
Mobile SDK 13.2.1+✅ "Login for Admin" menu item enables browser-based phishing-resistant login

 

솔루션

Supported Login Paths for PRMFA on Mobile

Option 1 :  "Login for Admin" Button (Recommended for Admins)

Available from Salesforce Mobile App v262.010+ and Mobile SDK 13.2.1+.
The "Login for Admin" button routes the admin through the system browser (Safari on iOS, Chrome on Android) instead of the embedded WebView, enabling the FIDO2/WebAuthn passkey prompt.
Steps:

  1. On the mobile app login screen, tap the gear icon (⚙️)
  2. Tap "Login for Admin"
  3. Complete passkey / built-in authenticator authentication in the system browser

    NOTE : If the "Login for Admin" button is not visible, the app version is likely below v262.010. Instruct the user to update the Salesforce Mobile App from the App Store / Google Play.

Option 2  : "Login with Email" with Native Browser Auth Enabled

Works for all users when the org is configured to use the native browser for authentication.
Prerequisites - enable in Setup:

  1. Go to Setup → My Domain → Authentication Configuration
  2. Enable "Use the native browser for user authentication on iOS" and/or "Use the native browser for user authentication on Android"

Steps:

  1. On the mobile app login screen, tap "Login with Email" (NOT the environment / domain URL tile)
  2. Authentication will route through Safari (iOS) or the system browser (Android)
  3. Complete passkey / built-in authenticator authentication in the browser

Passkey Registration Requirements for Mobile : 

Passkeys are device-bound. A passkey registered on desktop (e.g., via Windows Hello or a cross-device QR code flow) cannot be used on mobile.
To complete PRMFA on mobile, the user must have an iOS- or Android-native biometric passkey registered:

  1. On the mobile device's Safari/Chrome browser (not inside the Salesforce Mobile App), navigate to your Salesforce org
  2. Go to Setup → Users → [User's Advanced User Details] → Built-in Authenticators → Add
  3. Complete Face ID or Touch ID registration on the device

    NOTE :A passkey created via a cross-device QR code flow (e.g., scanning a QR code on a desktop screen with the phone's camera) is not the same as a native device biometric passkey. The user must register a native iOS/Android biometric passkey for mobile logins to work.

    Also refer to :  Register Built-in Authenticator

    The same limitations apply to the Field Service Mobile App and other apps built on Mobile SDK.
    • Option 1 (Admin users): Use the "Login for Admin" option (gear icon → Login for Admin)
    • Option 2 (All users): Enable "Use the native browser for user authentication on Android/iOS" in Setup → My Domain, then use the My Domain URL to log in , this forces authentication through the system browser

    Also refer to :  Enable Passwordless Login with Passkeys | Using Advanced Authentication

    SSO Considerations on Mobile

    If the customer's SSO Identity Provider (IdP) is configured to emit a phishing-resistant AMR/ACR value (e.g., from Entra ID with the correct Conditional Access configuration), Salesforce will honor that signal and not issue an additional PRMFA challenge after SSO login.
    Important: Even with Native Browser Auth enabled and the SSO connection corrected, the Salesforce Mobile App (Android) on Entra ID SSO may complete authentication without surfacing a phishing-resistant MFA prompt if Entra ID's Conditional Access policy is not scoped to require phishing-resistant MFA, specifically for the Salesforce SP-initiated SSO flow. Login History entries for mobile logins may also not reflect the expected MFA/AMR information. 
    If the SSO IdP emits only a standard MFA signal (e.g., phoneappnotification from ADFS or Entra ID without phishing-resistant Conditional Access), Salesforce will intercept the login and require the admin to register and use a Salesforce-native phishing-resistant method.
    Known Entra ID + Salesforce Mobile App limitations:

    NOTE : Migrating from ADFS to Entra ID for phishing-resistant SSO may cause issues with the native Salesforce Mobile App if Intune-managed device policies are in place. Recommend a sandbox test of mobile app behavior before production rollout.

    LimitationDetail
    Embedded WebView does not support FIDO2/WebAuthnPasskey prompt cannot be surfaced inside the native app - requires browser context
    Cross-device passkeys (QR code) not supported in mobile appMust register a device-native biometric passkey via the device's browser
    Mobile SDK ≤ 13.2.0 cannot support PRMFAMust upgrade to 13.2.1+ or pre-configure advanced auth
    enableUnifiedPasskeyExperience flag may cause silent failuresWhen Security Keys are ON and Built-in Authenticators are OFF, passkey flows may time out silently


    Troubleshooting: Admin Completely Blocked on Mobile

    If an admin is fully locked out (cannot login via any mobile path):
    1. Check app version :  confirm Salesforce Mobile App is v262.010+ for "Login for Admin" availability. If below v262.010, update from App Store / Google Play 
    2. Check Native Browser Auth setting in Setup → My Domain → Authentication Configuration. After saving, the user must fully log out of the app and reopen it ,  the app caches the auth flow and a restart is required 
    3. Test in Safari/Chrome directly : have the user open Safari on their iPhone, navigate to the Salesforce My Domain URL, and attempt Face ID login. If it works in Safari but not the app, the toggle is working but the app needs a clean restart or reinstall
    4. Verify passkey type :  confirm the registered passkey is a device-native biometric (not a cross-device QR passkey). Go to Setup → Advanced User Details → App Registration: Built-In Authenticator and verify registrations
    5. Watch for passkey overwrite :  Salesforce stores one built-in authenticator registration slot by default. Registering iPhone Face ID may have overwritten a previously registered desktop passkey (e.g., 1Password FIDO2). If the desktop passkey disappeared, re-register it from the desktop browser (Chrome) ,  both can coexist. 
    6. Check/Consider AdminPasskeysOptOut extension :  if the org cannot surface the passkey prompt and the admin has no other path, verify whether AdminPasskeysOptOut has been granted. If not, consider requesting it
    7. Check enableUnifiedPasskeyExperience flag interaction :  go to Setup → Identity Verification and confirm "Built-in Authenticators" is enabled and check the "Security Keys" status. When Security Keys are ON and Built-in Authenticators are OFF, passkey flows may time out silently
    8. Issue a one-time temporary login code : Salesforce Support can issue a one-time temporary login code as a last resort. This is session-specific; the underlying config must be fixed before the next login.

      Note : Regarding Step-Up Authentication on Mobile

      Step-up authentication (triggered when a user views or exports a report/dashboard) is completely separate from the PRMFA login challenge and is not resolved by "Login for Admin." 
      How the cooldown works:
      • The cooldown (default 120 minutes) is a grace period, not a re-prompt interval
      • User accesses a report → step-up challenge fires once
      • All subsequent report/dashboard accesses within the window → no re-challenge
      • After the window expires, the next access triggers a new challenge
      • This behavior is identical on mobile and desktop
      For standard users on mobile: challenged using their registered Salesforce MFA method (Salesforce Authenticator, biometrics, etc.), or email/SMS OTP as fallback.
      For PRMFA users (admins) on mobile: when the step-up challenge fires, they use their registered phishing-resistant method.

    Login for Admin" handles the login-time PRMFA challenge only. It does not bypass or change step-up authentication challenges triggered by report/dashboard access. Admins will still receive step-up challenges after logging in, even via "Login for Admin."

    Please also see : 

    MFA and Phishing-Resistant MFA Post-Enforcement Passkey Prompts and Extension Behavior



Knowledge 기사 번호

005390712

 
로드 중
Salesforce Help | Article