Phishing-resistant Multi-Factor Authentication (MFA) for privileged users and admins

Note Salesforce updates are subject to change beyond our control. Sage People attempts to maintain our content in alignment: for the most up to date information, refer to Salesforce documentation.

What's happening?

Salesforce is enforcing phishing-resistant Multi-Factor Authentication (MFA). This is for all users with the System Administrator profile, Modify All Data, View All Data, Customize Application, or Author Apex permissions. The change applies to direct UI logins and Single-Sign-On (SSO) logins, across both production and sandbox orgs.

Different MFA types

Tier Direct Salesforce Login (Salesforce MFA verifiers) SSO (AMR/ACR Signals from your Identity Provider) Result
Phishing-resistant MFA Security Keys (WebAuthn), Built-in Authenticators (Touch ID, Windows Hello) cert, fido, fido2, fpt, hwk, iris, pin, pki, pop, retina, sc, smartcard, swk, TLSClient, user, vbm, wia, x509 Successful login.
Standard MFA Salesforce Authenticator, TOTP Apps (Google/Microsoft Auth), and Admin-Generated Temporary Verification Codes face, mobiletwofactorcontract, multipleauthn, okta_verify, passkey, webauthn Login blocked until enrollment and use of phishing-resistant MFA verifiers.
Weak/no MFA No MFA pwd, sms, tel, email Login blocked until enrollment and use of phishing-resistant MFA verifiers.

 

  • Sandboxes: Starting 1 October, 2026, staggered over approximately seven days

  • Production: Starting 1 October, 2026, staggered over approximately 30 days

Will this affect you?

If any users with the permissions we listed above don't log in via Phishing resistant MFA methods, they can't use the system. If they don't use SSO where your identity provider sends a phishing-resistant MFA signal (AMR/ACR), they can't log in.

The system will block users from logging in until they register a phishing-resistant MFA method.

Note Of the standard profiles Sage People provides, this change only affects System Administrators. However, we recommend checking the permissions of any custom profiles or permission sets you've added.

Recommended action

Ensure any users with the permissions above who log in directly to Sage People are using Phishing resistant MFA methods.

If you use SSO, ensure your identity provider sends a phishing-resistant MFA signal (AMR/ACR) for any users with the above permissions.

For more information, see the Salesforce article Phishing-resistant MFA enforcement for privileged users and admins.

How to add passkey

  1. When you log in, the system presents you with a screen to create a passkey.

  2. Click Create Passkey.

  3. Add your passkey.

  4. Choose where to save your passkey. You can use Face ID, Touch ID, Windows Hello, password managers, or security keys.

  5. Once the system registers your passkey, it will prompt you to confirm the passkey to log in from the next time you do so.

Note The passkey is stored in the system you choose, you won't be able to log in to your account without this passkey. If you need to, you can add additional passkeys by going to your user account and clicking add built-in authenticators.

How to remove a passkey

  1. Go to Setup and select Users.

  2. Select the user with the passkey you want to remove.

  3. Click built-in authenticators.

  4. Click Remove next to the authenticator.