How to Disconnect Salesforce Authenticator and Set Up a New Device in Salesforce
This guide walks Salesforce admins through disconnecting a user’s Salesforce Authenticator app and setting up a new device for MFA. It addresses common scenarios like device loss or replacement, ensuring users can securely re-register without disabling MFA. By following clear steps — from disconnecting the old device to completing the new device verification — organizations maintain strong login security and comply with best practices. The post also outlines alternative verification methods and critical admin responsibilities for managing MFA devices.
- Only admins can disconnect a user’s Salesforce Authenticator device.
- Disconnecting removes the device but does not disable MFA for the user.
- Users must re-register MFA by entering a two-word phrase in the new Authenticator app.
- Alternative verification methods include Google Authenticator, Microsoft Authenticator, and SMS.
- Backup verification methods should be configured to avoid access issues.
Salesforce Authenticator is one of the most secure methods for Multi-Factor Authentication (MFA), helping protect user accounts and sensitive business data. Since a user can have only one Salesforce Authenticator app connected to their account at a time, replacing or losing a mobile device requires disconnecting the existing authentication before connecting a new device. If the Salesforce Authenticator app stops working or a user changes their phone, the easiest solution is to disconnect the current device and complete the setup process again. It’s also a recommended security practice to remove all verification methods from a user's account when they leave the organization, ensuring that no unauthorized access remains. In this blog, we’ll walk through the complete process of disconnecting Salesforce Authenticator and connecting a new device. Why Reset Salesforce MFA? Resetting Multi-Factor Authentication (MFA) helps maintain the security and integrity of your Salesforce organization.