Loading
Secure Your Salesforce Org
Sisällysluettelo
Valitse suodattimet

          Ei tuloksia
          Ei tuloksia
          Tässä on joitain hakuvinkkejä

          Tarkista avainsanojesi oikeinkirjoitus.
          Käytä yleisempiä hakutermejä.
          Laajenna hakua valitsemalla vähemmän suodattimia.

          Hae koko Salesforce-ohjeesta
          Understand MFA Requirements

          Understand MFA Requirements

          To protect users from security threats such as phishing, credential stuffing, and account takeovers, Salesforce requires multi-factor authentication (MFA) for all logins to Salesforce products. Understand MFA requirements based on the type of org, the type of user, and the user's level of access.

          Required Editions

          Available in: both Salesforce Classic and Lightning Experience
          Available in: all editions

          MFA is required for internal users who log in to active production orgs and sandboxes to access the Salesforce user interface (UI). The requirement applies to both direct login and single sign-on (SSO). The MFA requirement is described in the Notices and Licenses Information section of the Salesforce Trust and Compliance Documentation. Starting in June 2026, Salesforce enforces this requirement at login. After MFA is enforced, users can't log in without completing multi-factor authentication.

          Also, internal users with certain privileged permissions, such as admins, are required to use phishing-resistant verification methods for MFA starting in June 2026. See Phishing-Resistant MFA Requirement for Privileged Users for detailed information about this requirement.

          For both direct Salesforce logins and SSO, users can use the MFA services provided by the Salesforce Platform. For SSO logins, you can alternatively use an MFA service provided by the SSO provider. For example, if users log in with Okta, they can complete MFA with Okta's services before they're logged in to Salesforce. To use your SSO provider's MFA service, Salesforce requires the SSO provider to send specific authentication signals to Salesforce during SSO login.

          MFA isn't required for API logins, but MFA is required for automation or integration users who access the Salesforce UI. You can satisfy the requirement by programmatically completing MFA challenges.

          Let's break down the MFA requirement by org type, user type, and user's level of access.

          Determine the Org Type: Active or Non-Revenue?

          Active orgs include production and sandbox orgs, while non-revenue orgs include scratch orgs, trial orgs, and more. Use this table to understand how Salesforce categorizes orgs as active or non-revenue.

          Active or Non-Revenue? Org types MFA Requirement
          Active Production orgs and sandboxes, including Partial, Full, Developer, and Pro sandboxes Required
          Non-revenue Scratch orgs, trial orgs, Developer Edition orgs, Partner Developer Edition orgs, and Trailhead playgrounds Not required

          Determine the User Type: Internal or External?

          An internal user is anyone who has a standard user license and who can access your Salesforce org's UI. Internal users include admins, developers, privileged users, standard users, and users authorized to act on your company's behalf, such as partners and third-party agencies.

          External users can only access your company's Experience Cloud sites, ecommerce sites or storefronts, help portals, employee communities, and so forth.

          Internal or external? User License Types MFA Requirement
          Internal Required
          External Not required

          Determine the Internal User's Level of Access: Privileged or Non-Privileged?

          All internal users are required to use MFA, but users with a higher level of access to Salesforce must use more secure verification methods. Learn how Salesforce defines privileged access and how to satisfy MFA requirements.

          privileged or non-Privileged? Criteria MFA Requirements
          Privileged

          A user is considered privileged if they meet any of these criteria:

          • System Administrator profile OR
          • Author Apex user permission OR
          • Customize Application user permission OR
          • Modify All Data user permission OR
          • View All Data user permission

          Most Salesforce admins and developers are considered privileged.

          These users must use a phishing-resistant verification method to satisfy the MFA requirement.
          Non-privileged A non-privileged user is simply any user who doesn't meet the criteria for privileged access. Most employee users are non-privileged. These users can satisfy the MFA requirement with either phishing-resistant or standard verification methods.

          Enforcement Timeline

          Salesforce started enforcing MFA requirements in June 2026. The rollout is scheduled to conclude at the end of July 2026. For more information on the timeline, see these articles.

           
          Ladataan
          Salesforce Help | Article