New Salesforce MFA Rules for Admins & Privileged Users

New Salesforce MFA Rules for Admins & Privileged Users

New Salesforce MFA Rules for Admins & Privileged Users

User Image

Galina Kubis

Senior Salesforce Consultant

Salesforce enforces phishing-resistant multi-factor authentication (MFA) for privileged users – and further security changes are imminent.

In short: A code from an authenticator app will no longer be sufficient in the future.

The new rules will come into force in the Sandbox from June 22, 2026, and in the production environment from July 1, 2026.

Who is considered a privileged user?
System administrators and users with one of the following permissions:

  • Modify All Data

  • View All Data

  • Customize Application

  • Author Apex

Which authentication methods are permitted?

  • Physical security key (e.g., YubiKey, Google Titan Key)

  • Built-in authenticator (Face ID, Touch ID, etc.)

Salesforce recommends passwordless login with Passkeys for a faster and more secure experience.

If you use SSO, check the configuration of your Identity Provider. Either update your IdP to require phishing-resistant MFA, or enable Salesforce's own MFA for SSO logins – otherwise Salesforce will prompt you directly in the user interface to register a compliant method.

What are the next steps?

  • First, identify your privileged users.

  • Identify all users with the permission "Waive Multi-Factor Authentication for Exempt Users", as this permission will no longer work.

  • Ensure that both verification methods are enabled in the settings under "Identity Verification" in Setup.

    Identify Verification_Launch_Lane


  • Add one of the methods for yourself in your settings under "Advanced User Details" and encourage other privileged users to register their verification methods.


  • A backup method (second method) is highly recommended, as is a backup admin user in the organization.

Facebook Icon
LInkedin Icon
Paperclip Icon

More Articles

More Articles

More Articles

New Salesforce MFA Rules for Admins & Privileged Users

Warum Authenticator-Codes bald nicht mehr ausreichen – und wie Sie sich vorbereiten.

New Salesforce MFA Rules for Admins & Privileged Users

Warum Authenticator-Codes bald nicht mehr ausreichen – und wie Sie sich vorbereiten.

CRM in M&A: Why Niche Solutions Fail

Nischenlösung oder Plattform? Warum die falsche Wahl mehr kostet als die Lizenz.

CRM in M&A: Why Niche Solutions Fail

Nischenlösung oder Plattform? Warum die falsche Wahl mehr kostet als die Lizenz.

Launch Lane is your partner for smart Salesforce setups.

We support startups, SMEs, and medium-sized businesses in making their processes lean, their data usable, and their growth scalable – pragmatic, fast, and to the point.

Copyright © 2025 Launch Lane. All Rights Reserved.

Launch Lane is your partner for smart Salesforce setups.

We support startups, SMEs, and medium-sized businesses in making their processes lean, their data usable, and their growth scalable – pragmatic, fast, and to the point.

Copyright © 2025 Launch Lane. All Rights Reserved.

Launch Lane is your partner for smart Salesforce setups.

We support startups, SMEs, and medium-sized businesses in making their processes lean, their data usable, and their growth scalable – pragmatic, fast, and to the point.

Copyright © 2025 Launch Lane. All Rights Reserved.