Loading
Government Cloud
Índice de materias
Seleccionar filtros

          No hay resultados
          No hay resultados
          Estas son algunas sugerencias de búsqueda

          Compruebe la ortografía de sus palabras clave.
          Utilice términos de búsqueda más generales.
          Seleccione menos filtros para ampliar su búsqueda.

          Buscar en toda la Ayuda de Salesforce
          Multi-Factor Authentication in Government Cloud

          Multi-Factor Authentication in Government Cloud

          Multi-factor authentication (MFA) is a contractual requirement for all Salesforce Government Cloud customers. Understanding how MFA works across direct logins, external Experience Cloud sites, and single sign-on (SSO) configurations helps your agency enforce strong authentication consistently and avoid gaps in coverage. These recommended settings ensure that customers configure their Salesforce Orgs in a secure and compliant manner to meet customer defined and industry specific requirements.

          Required Editions

          Available in: Enterprise and Unlimited Editions
          Version 1.0
          Last Updated May 2026

          Multi-factor authentication (MFA) requires users to verify their identity using at least two independent methods before gaining access to Salesforce—typically a password combined with a time-based verification code, authenticator app, hardware security key, or biometric method. MFA protects against credential theft, phishing, and account takeover attacks, which are especially consequential in government environments where sensitive agency data is at stake. For Salesforce Government Cloud, MFA is a contractual requirement for all direct user logins to production orgs. The Salesforce platform enables MFA by default in production environments. Three distinct user populations may require separate MFA configurations, each with its own setup path:

          • Internal org users logging in directly with a username and password. MFA can be enforced for all users org-wide through a single Identity Verification setting.
          • External Experience Cloud site users accessing agency portals or community sites. MFA is not contractually required for this population, but agencies may choose to enable it based on their risk posture.
          • Users authenticating through single sign-on (SSO) via a third-party identity provider (IdP). Agencies have two options: delegate MFA to the IdP, or use Salesforce's built-in MFA service for the SSO flow.

          Regardless of login method, session security levels must be correctly configured. Multi-Factor Authentication must appear in the High Assurance column on the Session Settings page for MFA to enforce elevated access controls on protected resources. Salesforce now also enforces Device Activation for certain SSO logins where the identity provider does not provide sufficiently secure authentication. This is an automatic platform enforcement designed to prevent account takeover when existing IdP security controls are insufficient.

          • Enable Multi-Factor Authentication in Government Cloud
            Enable multi-factor authentication (MFA) for all users in your Salesforce Government Cloud Plus org—including internal users logging in directly, external Experience Cloud site users, and users authenticating through single sign-on (SSO). Follow these procedures to configure MFA for each login scenario and verify that session security levels are correctly set.
           
          Cargando
          Salesforce Help | Article