With recent Salesforce Security changes, Admin Users will need to setup either Touch ID or a Passkey to continue logging into Salesforce. Platform users will also need to use multi-factor authentication such as the Salesforce authenticator app. However, Admins cannot use SF Authenticator and must use an even more secure MFA method.
Under Security Controls > Identity Verification
Be sure that the following settings are enabled.
This will allow Admins to Register their Touch ID or Passkey.
NOTE: If the settings are greyed out for Touch ID and Passkey like the screenshot below. This means the feature is already enabled as part of the Org's My Domain settings. All Users will need to use Touch ID or a Passkey when this feature has been enabled within My Domain.
Next, go to the Admin's User page.
NOTE: If the Admin has already tried setting up a Passkey or Touch ID and it was not successful in allowing them to Login, you will want to Delete the Built-In Authenticator record.
On the User Detail page, go to the Built In Authenticators related list and Delete the record.
This will force the Admin User to create a new Touch ID or Passkey the next time they login.
Once successfully logged in using the Passkey or Touch ID, the Admin will need to Register the Passkey or Touch ID from their User Detail page.
From the User Detail page, locate Security Key (U2F or WebAuthn) and click Register
Using the Salesforce Data Loader
Logging in to use the Salesforce Data Loader will also now require additional identify verification. If the Admin is having challenges using the Data Loader after the Passkey or Touch ID have been implemented, you can try these solutions:
Go to Session Settings
In the Session Security Levels section, move Username Password to the High Assurance column.
Next, go to the User who was unable to login via Data Loader, look at the failed login attempt in the User's Login history and copy the IP Address they are using.
Now that you have the IP Address, we will need to Whitelist the IP Address.
Go to Network Access settings
Add a New Trusted IP address. Paste in the value from the Login history for the IP Address being used by the Data Loader user.
Save the record.