With single sign-on (SSO), users log in to Salesforce from another site, like Google (the
SSO identity provider). Salesforce requires multi-factor authentication (MFA) when logging in via
SSO. Here's how you can use your SSO identity provider's MFA service to satisfy the requirement.
With this SSO flow, users log in to the identity provider and complete MFA before they're
redirected to Salesforce.
Required Editions
Available in: both Salesforce Classic and Lightning Experience
Available in: all editions
User Permissions Needed
To view SSO settings:
View Setup and Configuration
To edit SSO settings:
Customize Application
AND
Modify All Data
To monitor logins:
Monitor Login History
OR
Manage Users
To use your SSO provider's MFA service, your provider must send supported Authentication
Methods References (AMR) or Authentication Context Class Reference (ACR) values. For a deeper
explanation of what this means and how it works, see Overview: MFA with an SSO Identity
Provider.
Determine what MFA method strength Salesforce requires for the user.
Privileged users (System Administrator profile or the Author Apex, Customize
Application, Modify All Data, or View All Data user permissions)—phishing-resistant MFA
methods are required.
Non-privileged users (anyone who doesn't have privileged permissions)—either
phishing-resistant or standard methods can satisfy the MFA requirement.
Review supported AMR and ACR values for the user's level of access by going to this knowledge artice and searching for Authentication
Strength Tiers.
Work with your SSO identity provider to send a supported value to Salesforce. This step
depends on your identity provider.
Tip If you already have MFA set up, it's possible that your SSO provider sends a
supported value to Salesforce. Use the instructions in step 4 to check.
Confirm that Salesforce receives the signals correctly.
Log in to Salesforce from the SSO provider.
From Setup, in the Quick Find box, enter Login, and then select
Login History.
Click Create New View.
Follow the steps to name the view and to select filter criteria.
For Select Fields to Display, add Authentication Context Class Reference
or Authentication Method Reference to Selected
Fields.
Save the view.
Look for an entry for your recent SSO login. Confirm that the value in the
Authentication Context Class Reference or Authentication
Method Reference field matches a supported value for the type of user.
Did this article solve your issue?
Let us know so we can improve!
Loading
Salesforce Help | Article
Cookie Consent Manager
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.