Phishing-Resistant MFA Requirement for Privileged Users
Salesforce requires extra security for internal user accounts that have a higher level
of access, such as admin accounts. These users must complete MFA using a phishing-resistant
method, such as a passkey or security key. This requirement applies to direct and single sign-on
(SSO) logins for active production and sandbox orgs.
Required Editions
Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
Phishing is a social engineering technique used to acquire sensitive information. Phishers
masquerade as a trustworthy person or company and convince users to give away sensitive
information. For example, phishers convince users to enter their password on a fake website.
Phishing-resistant MFA methods prevent these attacks because they're bound to one website,
the domain for your Salesforce org. They can't be used on a phisher's illegitimate website.
Phishing-resistant methods include passkeys, which let users log in with Touch or Face ID,
Windows Hello, password managers, or security keys.
For the phishing-resistant requirement, an internal user is considered privileged if they
meet any of these criteria:
System Administrator profile OR
Author Apex user permission OR
Customize Application user permission OR
Modify All Data user permission OR
View All Data user permission
For direct logins, Salesforce requires these users to complete MFA using a passkey (built-in
authenticator or security key). With the enforcement of phishing-resistant MFA,
privileged users who don't have a passkey are prompted to set one up to log in. To save time
and clicks, you can also enablepasswordless login with passkeys, which allows users
to log in with just their username and passkey. This is the fastest and easiest way to log
in to Salesforce directly.
For SSO logins, you can meet the requirement by using a phishing-resistant method from your
SSO provider. For example, if your SSO provider is Okta, users can log in and complete MFA
in Okta before being redirected to Salesforce. To use this option, your SSO provider must
send properly formatted authentication signals that Salesforce recognizes as
phishing-resistant. Otherwise, users are required to create a passkey before they can finish
logging in to Salesforce. See MFA with an SSO Identity Provider.
Phishing-resistant MFA doesn't work with automation or integration user accounts. Consider
removing permissions if possible and completing MFA challenges programmatically with a third-party authenticator app.
For use cases that require automation users to have privileged permissions, contact
Salesforce Customer Support.
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.