Audit Report for Upcoming MFA Requirements
Salesforce is enforcing three key MFA security requirements in 2026: MFA for all internal users, phishing-resistant MFA for privileged users, and step-up authentication for report exports. Admins must audit current MFA registrations using the Identity Verification Methods report and supplement it with privilege data and SSO identity provider assessments. Phishing-resistant MFA requires WebAuthn/FIDO2 methods, which differ from standard TOTP apps, and SSO configurations must pass specific AMR/ACR signals to ensure compliance. Additionally, protecting report exports requires step-up MFA verification with fallback challenges for SSO users lacking Salesforce MFA. The article outlines practical auditing steps and highlights gaps in reporting for SSO users to prepare orgs before enforcement deadlines.
- Use the Identity Verification Methods report to identify users lacking MFA registration.
- Audit privileged users for phishing-resistant MFA compliance using User Access & Permissions Assistant.
- Confirm your Identity Provider passes correct AMR/ACR signals for SSO MFA compliance.
- Check user contact info to ensure step-up authentication fallback via email/SMS works for report exports.
- Review and proactively manage MFA bypass permissions before enforcement begins.
If you’re a Salesforce admin or architect right now, your inbox has been busy. Salesforce has been signaling for months that 2026 is the year enforcement stops being theoretical. Three distinct security requirements are now actively rolling out — and if you haven’t already built the reports to audit your org’s compliance against each one, this post is your starting point. We’ll cover what each requirement demands, which Salesforce reporting tools address it, and — critically — where the standard Identity Verification Methods report type hits a wall for SSO users. The Three Requirements You Need to Know Requirement 1: MFA for All Employee Users Prepare for MFA Enforcement for All Employee Users This is the broad baseline. Salesforce is enforcing multi-factor authentication for all internal users — both direct UI logins and SSO logins — across production and sandbox orgs. The enforcement window began in sandboxes on June 22, 2026 and rolls into production starting July 20, 2026.