Loading
Secure Your Salesforce Org
Troubleshoot When a User Can't Create a Passkey

Troubleshoot When a User Can't Create a Passkey

Help users resolve passkey registration issues with their browser, device, or operating system after they select Create Passkey.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
User Permissions Needed
(Salesforce admins) To view identity verification settings: Customize Application

Users can encounter this issue in these ways.

  • The browser prompt times out or shows This device cannot be used.
  • Nothing happens after the user clicks Create Passkey in the passkey prompt.
  • After the user selects Cancel in the browser dialog, an error message prevents them from continuing.

Passkey Requirements

Using a passkey requires a supported browser, device, and operating system.

  • A supported browser: Chrome, Edge, Firefox, or Safari.
  • At least one way for the user to verify their identity:
    • Apple device users: A password-protected user account, Face ID, Touch ID, or another method supported by your Mac, iPhone, or other Apple device.
    • Windows users: Windows Hello with a PIN, fingerprint scanner, or face scanner.
    • A physical security key, such as a YubiKey or Titan key.
    • Another device, such as a phone or tablet, that supports passkeys. On some browsers, devices, and operating systems, you can use your other device to log in. Use your phone or tablet to scan a QR code that appears on the device where you want to log in. Then verify your identity by using the passkey on your phone or tablet.

Users: Verify Passkey Requirements

Verify that your browser, device, and operating system support passkeys for MFA.

  1. Confirm that you use a supported browser: Chrome, Edge, Firefox, or Safari.
  2. Confirm that your device and operating system support passkeys. For instructions, see the documentation for macOS and Windows.
  3. If your current device doesn’t support passkeys, and you don’t have a hardware security key, check whether you have another device that supports passkeys. For example, use a phone or tablet with a device PIN or Face ID to log in to your Salesforce account on another device.
  4. For detailed steps to create a passkey, see Create a Passkey.

Admins: Understand Org-Level Passkey Settings

Passkeys are enabled at the org level. As part of MFA enforcement, Salesforce sets the verification method settings on the Identity Verification page in Setup. Admins don’t need to configure these settings.

  • “Let users verify their identity with a built-in authenticator (passkey) such as Touch ID or Windows Hello”: on.
  • “Let users verify their identity with a physical security key (passkey) such as U2F or WebAuthn”: on.
  • “Show all permitted verification method options for MFA registration”: off. With this setting off, MFA registration begins with passkeys instead of showing all verification methods.
 
Laster
Salesforce Help | Article