Configure Phishing-Resistant MFA for Salesforce System Administrators
(Windows Hello or Mac Touch ID)
Overview
Salesforce is introducing new security requirements for System Administrator users.
To comply with these requirements, System Administrators should register a phishing-resistant authentication method such as:
- Windows Hello
- Mac Touch ID
- Passkeys
- Security Keys (FIDO2/WebAuthn)
This guide walks through the steps to enable the required Salesforce settings and register Windows Hello or Touch ID.
Step 1: Enable Identity Verification Settings
- Navigate to Setup.
- Search for Identity Verification in Quick Find.
- Open Identity Verification Settings.
- Enable the following options:
- Let users verify their identity with a built-in authenticator such as Touch ID or Windows Hello
- Show all verification method registration options instead of starting with built-in authenticators
- Allow passwordless login with passkeys
- Click Save.
Identity Verification Settings with the required options enabled.
Step 2: Configure Windows Hello or Touch ID on the Device
Before registering a built-in authenticator in Salesforce, make sure Windows Hello or Touch ID is configured on the device.
Windows
- Open Windows Settings.
- Navigate to Accounts > Sign-in Options.
- Configure one or more of the following:
- PIN
- Fingerprint Recognition
- Facial Recognition
Mac
- Open System Settings.
- Select Touch ID & Password.
- Configure Touch ID using your fingerprint.
Step 3: Register Windows Hello or Touch ID in Salesforce
- Log in to Salesforce.
- Click your profile picture and select Settings.
- Open Advanced User Details.
- Under Built-In Authenticators, click Add.
- Complete the identity verification process if prompted.
- Enter a name for the authenticator.
- Follow the prompts to register Windows Hello or Touch ID.
Registering a built-in authenticator from Advanced User Details.
Step 4: Verify the Login Experience
After registration is complete:
- Log out of Salesforce.
- Log back in.
- Verify that Windows Hello or Touch ID is available during login.
Note: Once registered, Windows Hello or Touch ID may become the preferred authentication method for future logins.
Managing Authenticators
Users can manage their authenticators at any time.
- Open Settings.
- Navigate to Advanced User Details.
- Rename or remove authenticators as needed.
Administrators can also manage authenticators from the user record.
Reviewing Authentication History
Administrators can review authentication activity and adoption.
- Navigate to Setup.
- Search for Identity Verification History.
- Review login activity and authentication methods used by users.
Frequently Asked Questions
Who should complete this setup?
All Salesforce System Administrators.
How long does setup take?
Most users can complete the setup in less than 10 minutes.
Can I register more than one authentication method?
Yes. Salesforce supports multiple authentication methods, and registering a backup method is recommended.
Can I remove or replace an authenticator later?
Yes. Authenticators can be managed from Advanced User Details at any time.