MFA: And… we’re back
Salesforce has announced new multi-factor authentication (MFA) requirements starting July 6, 2026 for sandboxes and July 20, 2026 for production environments. The timeline is shorter than expected, signaling urgency to enhance security across orgs. Salesforce professionals should prepare to enable MFA sooner rather than later, as delaying implementation only postpones improved protection. The overall message is to embrace the MFA rollout promptly to secure Salesforce access effectively.
- Plan MFA enablement for sandbox by July 6, 2026 and production by July 20, 2026.
- Treat the MFA timeline as firm to improve org security posture promptly.
- Communicate proactively with stakeholders about MFA changes and benefits.
- Avoid postponing MFA implementation to reduce security risks.
- Monitor Salesforce announcements for possible timeline updates or extensions.
Yesterday’s announcement sets the new MFA requirements to start on July 6, 2026 for sandboxes and July 20, 2026 for production. Here’s the full article on Salesforce. This is a shorter delay than I expected, and that may be a good thing. However, who’s to say they won’t extend this once more? As mentioned to a client before reading this announcement: Even if the requirements are delayed, the intention behind them is solid. Better to enable these features now and be more secure than to postpone their implementation. The takeaway Does this feel like a roller coaster yet?