Loading
Secure Your Salesforce Org
Recognize Passkey Creation Prompt Behavior

Recognize Passkey Creation Prompt Behavior

Users see prompts to create a passkey in several situations, including after a sandbox refresh. The “Waive Multi-Factor Authentication for Exempt Users” permission applies only to customers with an active temporary extension for multi-factor authentication (MFA) enforcement.

Required Editions

Available in: both Salesforce Classic and Lightning Experience
Available in: all editions

When Users See “Create a Passkey” Prompts

With MFA enforcement, Salesforce requires employee users who don’t meet MFA requirements to register an MFA verification method. Salesforce defaults to a passkey-first MFA registration flow for all employee users. Salesforce requires users with privileged permissions to set up passkeys or another phishing-resistant MFA method. Users who don’t have privileged permissions still see the passkey prompt first, but they can choose to set up other MFA verification methods.

Users with privileged permissions see this prompt when they log in directly.

Create a Passkey prompt during direct login

Users with privileged permissions see this prompt when they log in through a single sign-on (SSO) identity provider that doesn’t satisfy Salesforce MFA requirements.

Create a Passkey prompt during SSO login

Users without privileged permissions see this prompt. They can click Choose Another Verification Method to set up Salesforce Authenticator or a third-party authenticator app instead. However, passkeys are still the first option shown to all users in the MFA registration flow.

Note
Note

The Choose Another Verification Method option isn’t available to users with privileged permissions.

Create a Passkey prompt with other verification method options

Configure Passkeys After a Sandbox Refresh

After a sandbox refresh, users are prompted to create a passkey, even if they had one set up already. Newly refreshed sandboxes don’t inherit all verification settings from the production environment.

When users see these prompts, the required action varies based on the user’s login method.

Passkey Prompts for Users with the ‘Waive Multi-Factor Authentication for Exempt Users’ Permission

After MFA enforcement, users who previously had the ‘Waive Multi-Factor Authentication for Exempt Users’ permission see prompts to create a passkey. MFA enforcement causes this behavior. Unless your company has an approved temporary extension to use this user permission, this user permission no longer exempts users from MFA after enforcement.

Note
Note Unless your company has an approved temporary extension, the PermissionsBypassMFAForUiLogins API field for the “Waive Multi-Factor Authentication for Exempt Users” user permission is removed from the permission set and Profile object schema. After Salesforce removes the field, references to PermissionsBypassMFAForUiLogins can cause compilation errors that can block package installations or upgrades. Audit your code and metadata and remove all references to this field.

For more information about MFA behavior with extensions, see MFA and Phishing-Resistant MFA Post-Enforcement Passkey Prompts and Extension Behavior.

 
Laddar
Salesforce Help | Article