1. Log into your Salesforce org before enforcement starts.
2. Navigate to Setup:
- In the Setup menu, search for “Identity Verification.”
3. Enable Required Settings:
- Enable “Let users verify their identity with built-in authenticator passkey (such as Touch ID or Windows Hello).”
- Enable “Let users verify their identity with a physical security key passkey (such as UTF or WebAuthn).”
- Click Save.
4. Register a Passkey for Each Privileged User:
- Go to your user settings and then to “Advanced User Detail.”
- Find the setting for “Security Key UTF or WebAuthn” and click Register.
- Follow the prompts to save your passkey. If using a password manager like 1Password, it will automatically save the passkey upon registration.
Your account is now compliant with Salesforce’s phishing-resistant MFA requirements. If you use a different password manager, simply save the passkey in your chosen app.