Phishing-Resistant MFA Enforcement in Salesforce
Salesforce is enhancing security by enforcing phishing-resistant multi-factor authentication (MFA) for admins and privileged users who have powerful access. Traditional MFA methods like mobile TOTP apps and push notifications will no longer suffice for these users, as Salesforce requires more secure methods such as built-in device authenticators (Face ID, Touch ID) or physical security keys (YubiKey). The enforcement will begin in July 2026 for production and sandbox orgs, with detailed steps provided to configure and register phishing-resistant MFA methods. This update is critical for reducing the risk of phishing and session hijacking attacks on high-access Salesforce accounts.
- Privileged users must use phishing-resistant MFA like built-in authenticators or security keys.
- Enable and configure phishing-resistant verification methods via Salesforce Setup first.
- Register at least two MFA methods per user for backup and accessibility.
- SSO must pass phishing-resistant authentication claims for privileged user compliance.
- Regularly review and remove unnecessary privileged permissions to reduce risk.
Salesforce has required MFA for a while, but the security standard is now getting stronger. Salesforce will enforce phishing-resistant MFA for admins and other privileged users. This means some MFA methods that worked before may no longer be enough for high-access users. This post explains what phishing-resistant MFA means, who is affected, which verification methods are supported, and how to configure a built-in authenticator such as Face ID. What is Phishing-Resistant MFA? Phishing-resistant MFA is a stronger form of multi-factor authentication. It protects users from attacks that can steal or trick them into sharing verification codes. Instead of relying on one-time passwords or push approvals, it uses methods that are tied to the real login page. This makes it much harder for attackers to use fake websites or man-in-the-middle attacks. In Salesforce, phishing-resistant MFA usually means using a built-in authenticator, such as Face ID or Touch ID, or a physical security key.