Loading
Government Cloud
Innhold
Velg filtre

          Ingen resultater
          Ingen resultater
          Her er noen søketips

          Kontroller stavemåten i søkeordene.
          Bruk mer generelle søkebegreper.
          Velg færre filtre for å utvide søket.

          Søk i all Salesforce Hjelp
          Enable Multi-Factor Authentication in Government Cloud

          Enable Multi-Factor Authentication in Government Cloud

          Enable multi-factor authentication (MFA) for all users in your Salesforce Government Cloud Plus org—including internal users logging in directly, external Experience Cloud site users, and users authenticating through single sign-on (SSO). Follow these procedures to configure MFA for each login scenario and verify that session security levels are correctly set.

          Required Editions

          Available in: Enterprise and Unlimited Editions
          Version 1.0
          Last Updated May 2026

          As a safeguard against unauthorized account access, customers are contractually required to use multi-factor authentication (MFA) when accessing Salesforce products. MFA is a default part of the direct login experience for production orgs. For single sign-on (SSO) logins, customers can implement the free MFA functionality provided by Salesforce or use a SSO provider's MFA service.

          Procedure 1: Enable MFA for All Internal Users. To require MFA for every user logging in directly to your Salesforce org with a username and password:

          • From Setup, in the Quick Find box, enter Identity, then select Identity Verification.
          • Select Require multi-factor authentication (MFA) for all direct UI logins to your Salesforce org.

          After enabling org-wide MFA, verify session security levels:

          • From Setup, in the Quick Find box, enter Session, then select Session Settings.
          • Under Session Security Levels, confirm that Multi-Factor Authentication is listed in the High Assurance column.
            Note
            Note MFA is automatically enabled for all users in production orgs. For sandbox, trial, or developer orgs, enable MFA manually using the steps above.

          Procedure 2: Enable MFA for External Experience Cloud Site Users. Salesforce doesn't require MFA for external users, but customers can include this class of users in their MFA implementation. To apply MFA to external users accessing your Experience Cloud site:

          • From Setup, in the Quick Find box, enter Users, then select Profiles.
          • Edit the custom profiles assigned to your external Experience Cloud site users.
            Standard profiles cannot be edited.
          • In the General User Permissions section, select the Multi-Factor Authentication for User Interface Logins checkbox.
          • Click Save.

          Procedure 3: Enable MFA for SSO Logins Using Your Identity Provider. To delegate MFA challenges to your third-party identity provider (IdP):

          • Configure your third-party identity provider and SSO implementation.
            See Salesforce as a Service Provider.
          • From Setup, in the Quick Find box, enter Session, then select Session Settings.
          • Under Session Security Levels, confirm that your SSO configuration is in the High Assurance column.
            Note
            Note When users log in through an identity provider that is set to High Assurance, Salesforce grants high-assurance access directly and does not prompt users for an additional MFA verification.

          Procedure 4: Turn on MFA for SSO Using Salesforce MFA. If SSO is used for login, customers can turn on a SSO provider's MFA service or implement the free MFA functionality provided by Salesforce. To receive MFA challenges from your third-party identity provider:

          • Configure your third-party identity provider and SSO implementation.
          • From Setup, in the Quick Find box, enter Session, then select Session Settings.
          • In Session Security Levels, make sure your SSO configuration is in the High Assurance column.
            When users log in through an identity provider, they're granted high-assurance access and aren't prompted for an additional MFA verification. Customers can also use the free MFA services included in Salesforce to meet MFA requirements for SSO.

          To use Salesforce MFA for new or existing SSO configurations:

          • Enable MFA for your users.
            Salesforce automatically enables MFA for all users in production orgs. If that's not the case for your environment, see Enable MFA for Your Entire Org.
          • Enable MFA for your SSO configuration.
            On the setup page for your SAML or Auth Provider SSO configuration, enable the Use Salesforce MFA for this SSO Provider setting.
          • Verify that your session security level settings are correctly configured for Device Activation.
            Salesforce now requires Device Activation for certain SSO user logins.
            1. From Setup, in the Quick Find box, enter Session Settings, then select Session Settings.
            2. In Session Security Levels, make sure that your SSO provider is in the Standard column and Multi-Factor Authentication is in the High Assurance column.
            3. Save your changes.
          Note
          Note As part of ongoing efforts to implement stronger security measures, Salesforce now requires Device Activation for certain SSO user logins. This additional security step is enforced where SSO identity providers (IdPs) lack secure authentication or when existing security controls may not be robust enough to mitigate current threats. These proactive measures enhance protection against account takeover (ATO) and unauthorized access.
           
          Laster
          Salesforce Help | Article