Loading
Secure Your Salesforce Org
Inhalt
Filter auswählen

          Keine Ergebnisse
          Keine Ergebnisse
          Hier sind einige Suchtipps

          Überprüfen Sie die Schreibweise Ihrer Stichwörter.
          Verwenden Sie allgemeinere Suchbegriffe.
          Wählen Sie weniger Filter aus, um Ihre Suche auszuweiten.

          Gesamte Salesforce-Hilfe durchsuchen
          Phishing-Resistant MFA Requirement for Privileged Users

          Phishing-Resistant MFA Requirement for Privileged Users

          Salesforce requires extra security for internal user accounts that have a higher level of access, such as admin accounts. These users must complete MFA using a phishing-resistant method, such as a passkey or security key. This requirement applies to direct and single sign-on (SSO) logins for active production and sandbox orgs.

          Required Editions

          Available in: both Salesforce Classic and Lightning Experience
          Available in: all editions

          Phishing is a social engineering technique used to acquire sensitive information. Phishers masquerade as a trustworthy person or company and convince users to give away sensitive information. For example, phishers convince users to enter their password on a fake website. Phishing-resistant MFA methods prevent these attacks because they're bound to one website, the domain for your Salesforce org. They can't be used on a phisher's illegitimate website. Phishing-resistant methods include passkeys, which let users log in with Touch or Face ID, Windows Hello, password managers, or security keys.

          For the phishing-resistant requirement, an internal user is considered privileged if they meet any of these criteria:

          • System Administrator profile OR
          • Author Apex user permission OR
          • Customize Application user permission OR
          • Modify All Data user permission OR
          • View All Data user permission

          For direct logins, Salesforce requires these users to complete MFA using a passkey (built-in authenticator or security key). With the enforcement of phishing-resistant MFA, privileged users who don't have a passkey are prompted to set one up to log in. To save time and clicks, you can also enablepasswordless login with passkeys, which allows users to log in with just their username and passkey. This is the fastest and easiest way to log in to Salesforce directly.

          For SSO logins, you can meet the requirement by using a phishing-resistant method from your SSO provider. For example, if your SSO provider is Okta, users can log in and complete MFA in Okta before being redirected to Salesforce. To use this option, your SSO provider must send properly formatted authentication signals that Salesforce recognizes as phishing-resistant. Otherwise, users are required to create a passkey before they can finish logging in to Salesforce. See MFA with an SSO Identity Provider.

          Phishing-resistant MFA doesn't work with automation or integration user accounts. Consider removing permissions if possible and completing MFA challenges programmatically with a third-party authenticator app. For use cases that require automation users to have privileged permissions, contact Salesforce Customer Support.

          Enforcement Timeline

          Salesforce started enforcing phishing-resistant MFA in June 2026. The rollout is scheduled to conclude at the end of July 2026. For more information on the timeline, see Prepare for Phishing-Resistant MFA Enforcement for Privileged Users including Admins.

           
          Laden
          Salesforce Help | Article