Loading
Secure Your Salesforce Org
目录
选择筛选器

          没有结果
          没有结果
          以下是一些搜索提示

          检查关键字的拼写。
          使用更普遍的搜索词。
          选择更少的筛选器,并扩大搜索范围。

          搜索所有 Salesforce 帮助
          MFA Verification Method Tiers

          MFA Verification Method Tiers

          The multi-factor authentication (MFA) login process requires users to provide an identity verification method in addition to their username and password. Salesforce supports several types of verification methods, including passkeys (built-in authenticators and security keys) and authenticator apps. Some verification methods are stronger than others. Salesforce requires users with privileged permissions, such as admins, to use more secure methods.

          Important
          Important

          Salesforce started enforcing MFA requirements in June 2026. See these articles for more information.

          Salesforce categorizes verification methods into three categories based on how secure they are.

          1. Phishing-resistant verification methods are the most secure. Phishing is a type of cyberattack where bad actors trick users into giving access to their accounts. To convince users to give away their information, attackers masquerade as trustworthy people or companies. For example, attackers use social engineering tactics to get users to enter their username and password on a fake login page that looks legitimate.

            Phishing-resistant verification methods, such as fingerprint scans and hardware security keys, protect against these attacks because they can't be used with fake websites. For example, with Touch ID, the user enters their username and password, and then uses Touch ID on their device. The login works only with that user's fingerprint, and only on one website.

          2. Standard verification methods are strong, but don't offer the same protections as phishing-resistant methods. Standard MFA methods include authenticator apps that issue time-based one-time passwords (TOTPs), such as Salesforce Authenticator. For example, users enter their username and password, and then enter a six-digit code (the TOTP) to finish logging in.
          3. Weak methods are the least secure. They include verification codes sent via email or SMS. Email credentials can be compromised and mobile phone numbers can be intercepted via SIM swapping attacks or hacked mobile device accounts. Salesforce doesn't support these methods for internal users to log in with MFA. However, they can be used to complete step-up authentication after a user has already logged in with a secure MFA method.

          Here's an overview of each tier's associated requirements and supported verification methods.

          Security Tier MFA Requirements Direct Salesforce Login Verification Methods Single Sign-On Verification Methods
          Phishing-resistant

          Phishing-resistant methods are required for privileged internal users who meet any of these criteria:

          • System Administrator profile
          • Author Apex user permission
          • Customize Application user permission
          • Modify All Data user permission
          • View All Data user permission

          For users who don't have these privileged permissions, phishing-resistant methods satisfy the MFA requirement, but aren't required.

          Salesforce supports two types of passkeys for phishing-resistant MFA:

          • Built-in authenticators, which use a fingerprint, iris, or facial recognition scan, or a PIN or password. Examples include Touch ID or Face ID, Windows Hello, password managers, and security keys.
          • Security keys, which are small physical devices like YubiKeys that a user connects to their device.

          Alternatively, use certificate-based authentication. This method uses X.509 client certificates and mutual TLS (mTLS) for identity verification. Private keys stored in secure hardware ensure phishing and credential theft resistance. See Certificate-Based Authentication for details. This method satisfies the phishing-resistant MFA requirement without any additional factors.

          See this knowledge article for phishing-resistant authentication signals that your SSO provider can send to Salesforce. These signals include both Authentication Context Class Reference (ACR) and Authentication Methods References (AMR) claims.
          Standard Standard methods can satisfy the MFA requirement for internal users who don't have privileged permissions. See this knowledge article for standard ACR and AMR signals that your SSO provider can send to Salesforce.
          Weak These methods don't satisfy any MFA requirements. Weak methods include email and SMS. Salesforce doesn't support these methods for direct login to Salesforce orgs. Some weak values are documented in this knowledge article, but this list isn't exhaustive. Any value that isn't documented as phishing-resistant or standard is considered weak.
           
          正在加载
          Salesforce Help | Article