You are here:
Understand MFA Requirements
To protect users from security threats such as phishing, credential stuffing, and account takeovers, Salesforce requires multi-factor authentication (MFA) for all logins to Salesforce products. Understand MFA requirements based on the type of org, the type of user, and the user's level of access.
Required Editions
| Available in: both Salesforce Classic and Lightning Experience |
| Available in: all editions |
MFA is required for internal users who log in to active production orgs and sandboxes to access the Salesforce user interface (UI). The requirement applies to both direct login and single sign-on (SSO). The MFA requirement is described in the Notices and Licenses Information section of the Salesforce Trust and Compliance Documentation. Starting in June 2026, Salesforce enforces this requirement at login. After MFA is enforced, users can't log in without completing multi-factor authentication.
Also, internal users with certain privileged permissions, such as admins, are required to use phishing-resistant verification methods for MFA starting in June 2026. See Phishing-Resistant MFA Requirement for Privileged Users for detailed information about this requirement.
For both direct Salesforce logins and SSO, users can use the MFA services provided by the Salesforce Platform. For SSO logins, you can alternatively use an MFA service provided by the SSO provider. For example, if users log in with Okta, they can complete MFA with Okta's services before they're logged in to Salesforce. To use your SSO provider's MFA service, Salesforce requires the SSO provider to send specific authentication signals to Salesforce during SSO login.
MFA isn't required for API logins, but MFA is required for automation or integration users who access the Salesforce UI. You can satisfy the requirement by programmatically completing MFA challenges.
Let's break down the MFA requirement by org type, user type, and user's level of access.
Determine the Org Type: Active or Non-Revenue?
Active orgs include production and sandbox orgs, while non-revenue orgs include scratch orgs, trial orgs, and more. Use this table to understand how Salesforce categorizes orgs as active or non-revenue.
| Active or Non-Revenue? | Org types | MFA Requirement |
|---|---|---|
| Active | Production orgs and sandboxes, including Partial, Full, Developer, and Pro sandboxes | Required |
| Non-revenue | Scratch orgs, trial orgs, Developer Edition orgs, Partner Developer Edition orgs, and Trailhead playgrounds | Not required |
Determine the User Type: Internal or External?
An internal user is anyone who has a standard user license and who can access your Salesforce org's UI. Internal users include admins, developers, privileged users, standard users, and users authorized to act on your company's behalf, such as partners and third-party agencies.
External users can only access your company's Experience Cloud sites, ecommerce sites or storefronts, help portals, employee communities, and so forth.
| Internal or external? | User License Types | MFA Requirement |
|---|---|---|
| Internal | Required | |
| External | Not required |
Determine the Internal User's Level of Access: Privileged or Non-Privileged?
All internal users are required to use MFA, but users with a higher level of access to Salesforce must use more secure verification methods. Learn how Salesforce defines privileged access and how to satisfy MFA requirements.
| privileged or non-Privileged? | Criteria | MFA Requirements |
|---|---|---|
| Privileged | A user is considered privileged if they meet any of these criteria:
Most Salesforce admins and developers are considered privileged. |
These users must use a phishing-resistant verification method to satisfy the MFA requirement. |
| Non-privileged | A non-privileged user is simply any user who doesn't meet the criteria for privileged access. Most employee users are non-privileged. | These users can satisfy the MFA requirement with either phishing-resistant or standard verification methods. |
Enforcement Timeline
Salesforce started enforcing MFA requirements in June 2026. The rollout is scheduled to conclude at the end of July 2026. For more information on the timeline, see these articles.

