New MFA requirements are postponed
Salesforce has indefinitely postponed the enforcement of its new MFA requirements due to widespread unpreparedness among large enterprises. While some users found faster login options like Bitwarden passkeys, adoption has been uneven, leading to the delay. Salesforce professionals should continue using existing MFA methods as the secure standard and stay tuned for future updates before making changes. This postponement highlights the importance of readiness and flexibility when dealing with security mandates in Salesforce orgs.
- Salesforce has postponed new MFA enforcement indefinitely due to low readiness.
- Continue using MFA on your phone until further updates are provided.
- Adoption of alternative passkeys like Bitwarden is faster but not widespread yet.
- Large organizations need time to adjust to significant security changes.
- Watch official announcements closely for rescheduled enforcement timelines.
After hastily announcing rushed and severe new MFA requirements, Salesforce has now postponed its enforcement, indefinitely. This probably shouldn’t come as a surprise. I’m sure there are thousands of large corporations that were unprepared for this significant change. And I’m sure they beat their drums until Salesforce listened. What I’m actually surprised about is that Salesforce waited until the last possible minute to announce the postponement. To be honest, I find logging in with a Bitwarden passkey to be faster than using MFA with a mobile phone. So there were some gains to be had. But clearly not everyone was as quick to adopt passkeys. Here is the official announcement . The takeaway Keep calm and keep using MFA on your phone.