SOLVD BLOG

Salesforce Phishing-Resistant MFA Setup

Salesforce administrators have new security requirements to consider following the 2026 platform update. With Salesforce now enforcing phishing-resistant Multi-Factor Authentication (MFA) for privileged users, it’s crucial to ensure your org and team are fully prepared before these changes are rolled out.

This post highlights who is affected, what’s actually changing, and how admins can smoothly enable compliance ahead of enforcement dates.

Who Is Affected by Phishing-Resistant MFA?

With Salesforce’s new policies, phishing-resistant MFA is now mandatory for anyone who meets at least one of the following criteria:

  • Has the System Administrator profile
  • Possesses “Modify all data,” “View all data,” “Customize application,” or “Author Apex” permissions (including via permission sets)

This requirement applies to both Direct UI logins and Single Sign-On (SSO) logins, and is enforced in both production and sandbox environments.

What’s Changing in Authentication Methods?

Standard authenticator apps like Salesforce AuthenticatorGoogle Authenticator, and Microsoft Authenticator, as well as any TOTP app, are no longer sufficient for privileged users. These are now categorized as “Standard MFA”—which does not comply with the new requirements.

To pass Salesforce’s phishing-resistant MFA requirements, users must use a passkey registered with:

  • Touch IDFace ID, or Windows Hello
  • A hardware security key (e.g., Yubikey)
  • Passkeys stored in FIDO2-compliant password managers (e.g., 1Password, Bitwarden)

Enforcement Timeline

  • Sandboxes: Enforcement already began on July 10th, 2026.
  • Production Orgs: Rollout starts July 20th and continues through the first week of September 2026.

Important: Once this enforcement reaches your org, affected users will be blocked at login until a compliant authentication method is registered—there is no grace period. Always confirm the latest enforcement timeline on the official Salesforce help articles.

Step-by-Step: Setting Up Phishing-Resistant MFA in Salesforce

1. Log into your Salesforce org before enforcement starts.

2. Navigate to Setup:

  • In the Setup menu, search for “Identity Verification.”

3. Enable Required Settings:

  • Enable “Let users verify their identity with built-in authenticator passkey (such as Touch ID or Windows Hello).”
  • Enable “Let users verify their identity with a physical security key passkey (such as UTF or WebAuthn).”
  • Click Save.

4. Register a Passkey for Each Privileged User:

  • Go to your user settings and then to “Advanced User Detail.”
  • Find the setting for “Security Key UTF or WebAuthn” and click Register.
  • Follow the prompts to save your passkey. If using a password manager like 1Password, it will automatically save the passkey upon registration.

Your account is now compliant with Salesforce’s phishing-resistant MFA requirements. If you use a different password manager, simply save the passkey in your chosen app.

Stay Ahead of Enforcement

Don’t wait until the day Salesforce blocks your admin access. Enable these settings and test the process with all affected users now, ensuring smooth compliance and uninterrupted org management.

yellow cloud solvd logo
Testimonials

Ournclientsnsay

From my initial call with Spencer through project implementation with John and Evan, my experience with the SOLVD team was excellent. They were quick to understand our business needs, clear when explaining the reasoning behind proposed solutions, transparent when reporting on progress and timeline, and all around enjoyable to work with. Would highly recommend and looking forward to continue working with them in the future!

Veronica Wong Director of Operations at Pathstream

SOLVD was very straight forward with everything needed to complete the project. No surprises, no issues, and cost was aligned with the estimate. They made implementation easy and quick.

Matt Benzaquen Sr Manager, Sales Strategy at Instabug

As a rule, I'm pretty stingy with my recommendations. So it's a pleasure for me to recommend Solvd as a top-flight Salesforce consultancy. Solvd recently led our company's conversion to the Lightning interface and did it on time, on budget and made it easy for me and my team. I know I'll use their services again, and am confident they can do the same for you.

Tim Tuttle CFO at Relevate Health Group

HIGHEST RATED ON SALESFORCE