Hi all,
we are deploying MFA in our ORG (hurray!)
some of our users are using Microsoft Authenticator for Salesforce MFA and it works perfectly.
But users that using an (old) mobile (Samsung A3) can't connect Microsoft Authenticator App with Salesforce..
Once the scan the QR code to add the account to Microsoft Authenticator, Salesforce ask for the passcode (the 6-digit code that Microsoft Authenticator provides)...
but the generated code is always invalid and they cannot log in...
any ideas?
thanks!
@Veronika Lovrantova The way the OATH TOTP standard works is that the app on the phone and the Salesforce org have a shared key. Using this shared key and time, they are able to produce the same 6 digit code. The time is based on the current Unix time (i.e., the number of seconds elapsed since midnight UTC of January 1, 1970) and is therefore unaffected by timezones.
I suggest having the customer try a different TOTP app, like Google Authenticator. If it works, then there's likely an issue with Microsoft Authenticator on that particular device. If Google Authenticator also does not work, then it's likely that the phone's time is off.