Loading
Upcoming Mandatory Changes to Public Key Infrastructure (PKI)Read More
Salesforce Enforces New Security Requirements in Summer 2026Read More
Secure Your Salesforce Org
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Set Up MFA with an SSO Identity Provider

          Set Up MFA with an SSO Identity Provider

          With single sign-on (SSO), users log in to Salesforce from another site, like Google (the SSO identity provider). Salesforce requires multi-factor authentication (MFA) when logging in via SSO. Here's how you can use your SSO identity provider's MFA service to satisfy the requirement. With this SSO flow, users log in to the identity provider and complete MFA before they're redirected to Salesforce.

          Required Editions

          Available in: both Salesforce Classic and Lightning Experience
          Available in: all editions
          User Permissions Needed
          To view SSO settings: View Setup and Configuration
          To edit SSO settings:

          Customize Application

          AND

          Modify All Data

          To monitor logins:

          Monitor Login History

          OR

          Manage Users

          To use your SSO provider's MFA service, your provider must send supported Authentication Methods References (AMR) or Authentication Context Class Reference (ACR) values. For a deeper explanation of what this means and how it works, see Overview: MFA with an SSO Identity Provider.

          1. Determine what MFA method strength Salesforce requires for the user.
            • Privileged users (System Administrator profile or the Author Apex, Customize Application, Modify All Data, or View All Data user permissions)—phishing-resistant MFA methods are required.
            • Non-privileged users (anyone who doesn't have privileged permissions)—either phishing-resistant or standard methods can satisfy the MFA requirement.
          2. Review supported AMR and ACR values for the user's level of access by going to this knowledge artice and searching for Authentication Strength Tiers.
          3. Work with your SSO identity provider to send a supported value to Salesforce. This step depends on your identity provider.
            Tip
            Tip If you already have MFA set up, it's possible that your SSO provider sends a supported value to Salesforce. Use the instructions in step 4 to check.
          4. Confirm that Salesforce receives the signals correctly.
            1. Log in to Salesforce from the SSO provider.
            2. From Setup, in the Quick Find box, enter Login, and then select Login History.
            3. Click Create New View.
            4. Follow the steps to name the view and to select filter criteria.
            5. For Select Fields to Display, add Authentication Context Class Reference or Authentication Method Reference to Selected Fields.
            6. Save the view.
            7. Look for an entry for your recent SSO login. Confirm that the value in the Authentication Context Class Reference or Authentication Method Reference field matches a supported value for the type of user.
           
          Loading
          Salesforce Help | Article