Looking for a Salesforce PO/PM to confirm the intended purpose and general availability of these new system permissions. Any out there that can help?
* MFA - Getting Started *
- Letzte Aktivität
- Erstellt am
- Alle Fragen
- Fragen mit einer akzeptierten Antwort
- Unbeantwortete Fragen
- Fragen ohne akzeptierte Antwort
It just started today, 7/22, that when staff export reports, they are asked for verification code.
When they enter the code from the authentication app, it doesn't work and just keep looping.
I tried to generate temporary verification code via staff's user account. An email was sent to them but no code and no link, nothing. I don't have the code either. so dead-end.
We use MS SSO for staff to get in Salesforce. Our IT people just enabled passkey method on the network. One staff set up passkey successfully and she could now export reports fine. However, two other staff can't set up passkey, the same, got stuck on verification code screen.
I don't know what else to do. Please advise.
31. Aug., 17:33 @Max Wilson I don't think so. Are you the Salesforce Sys Admin or are you a user and trying to get info for the admin? I'm happy to help if you can tell me more.
FIX: “Problem Verifying Your Identity” after Salesforce MFA/passkey changes
I wanted to share the solution to a frustrating Salesforce login problem in case it saves someone else a lot of troubleshooting.
I am the sole user/System Administrator of my Salesforce org. After the recent MFA/passkey changes, I began receiving this error when trying to log in:
“Problem Verifying Your Identity. To log in, you need both a higher access level and an identity verification method. Contact your administrator to gain login access.”
I already had Salesforce Authenticator and a registered passkey. The passkey worked on My Macbook laptop but I had inconsistent or failed logins on my iMac desktop. I tried different browsers, clearing cache, temporary verification codes, etc.
I eventually had a Google Meet with a Salesforce support technician. After I shared my screen, he spotted the problem almost immediately:
Lightning Login was still enabled on my user account.
The fix took about one minute:
Profile photo → Settings → My Personal Settings → Advanced User Details → scroll down to Lightning Login → Cancel
After canceling Lightning Login, I was immediately able to log into Salesforce normally using Google Chrome and my passkey.
For anyone encountering this specific error after the new phishing-resistant MFA/passkey rollout, I strongly recommend checking whether Lightning Login is still enabled before spending hours troubleshooting passkeys, browsers, MFA settings, or devices.
I hope this saves someone else the time it took me to find the solution.
31. Aug., 16:55 I’m seeing similar behavior. We use Azure Active Directory SSO, but after users click “Log in using Azure Active Directory,” Salesforce redirects them to its Create a Passkey screen and pushes additional Salesforce authentication/verification setup.
Using a Microsoft Authenticator one off password gets the user in, but the Salesforce passkey prompt returns. That’s the issue I’m trying to resolve... users are authenticating through our SSO provider, yet Salesforce is still inserting its own enrollment/verification flow.
Last week, I created a passkey for my Sandbox org and was able to log in without any problems for several days.
Today, after not logging in over the weekend, I was unable to authenticate beyond the screen below. Every time I clicked the "Verify Your Identity" button, the page simply reloaded.
I asked another System Administrator for help, and they deleted the
Security Key (U2F/WebAuthn)associated with my account. Now I'm stuck on the screen below and I'm unable to register a new passkey. The same issue is occurring: whenever I click the button, the page simply reloads.
Is anyone having the same problem? I tried this at two different browsers and the same error occured.
25. Aug., 22:02 FIX: “Problem Verifying Your Identity” after Salesforce MFA/passkey changes
I wanted to share the solution to a frustrating Salesforce login problem in case it saves someone else a lot of troubleshooting.
I am the sole user/System Administrator of my Salesforce org. After the recent MFA/passkey changes, I began receiving this error when trying to log in:
“Problem Verifying Your Identity. To log in, you need both a higher access level and an identity verification method. Contact your administrator to gain login access.”
I already had Salesforce Authenticator and a registered passkey. The passkey worked on one computer but I had inconsistent or failed logins on another. I tried different browsers, clearing cache, temporary verification codes, etc.
I eventually had a Google Meet with a Salesforce support technician. After I shared my screen, he spotted the problem almost immediately:
Lightning Login was still enabled on my user account.
The fix took about one minute:
Profile photo → Settings → My Personal Settings → Advanced User Details → scroll down to Lightning Login → Cancel
After canceling Lightning Login, I was immediately able to log into Salesforce normally using Google Chrome and my passkey.
For anyone encountering this specific error after the new phishing-resistant MFA/passkey rollout, I strongly recommend checking whether Lightning Login is still enabled before spending hours troubleshooting passkeys, browsers, MFA settings, or devices.
I hope this saves someone else the time it took me to find the solution.
*** Important updates: MFA Enforcement Update: R1 Window Rescheduled to July 27-28 ***We wanted to give you a heads-up that the R1 MFA enforcement window has been updated. Here's what you need to know:
What Changed
The R1 enforcement window has moved from July 21–22 to July 27–28.
Why the Change
We made this adjustment to address a few things:
- Additional time was needed to fully process previously approved extensions
- Some SSO users on orgs with approved extensions were being unexpectedly prompted for MFA
If You Have an Approved Extension
Keep in mind that approved extensions can take up to 48 hours to take effect, so you may still see MFA prompts during that window.
If your org has an approved extension but you're still being prompted for a passkey, please refer to this Knowledge Article for detailed guidance on specific use cases.
What's Not Changing
- The MFA for All schedule remains the same
- R2a, R2b, Japan & Korea, and all subsequent release groups are on their original schedules
Where to Find the Latest Info
The PRMFA Knowledge Article has been updated to reflect the new R1 window — that's your best source for the current schedule and details.
Have questions? Drop them in the comments below and we'll do our best to help!
#MFA #Security

I have a new phone, and I downloaded my authenticator app and logged in. However, I don't know where to find the qr code to finish setting up for accessing Salesforce.
27. Juli, 15:06 Experiencing the same issue. I have been exporting reports for years and all of a sudden this morning I have to authorize exports using the authenticator app???? There's no way to bypass it, and I really need this report and the others I am trying to export. The authenticator app doesn't even work when trying to set it up; no screen pops up in Salesforce that prompts you to enter the phrase the app wants you to type in.
Received an security notification from Salesforce regarding Phishing-Resistant MFA for Privileged users. We use Entra SSO SAML, the SAML tracer shows weak, is there any configuration changes that needs to be done on Single sign on page in salesforce? I do Know there are some changes to be done on the IDP side but I'm not sure what changes to be made at Salesoforce end to meet ACR/AMR requirement. @* MFA - Getting Started *@* Salesforce Administrators *@* Customer Success *@* Salesforce Developers *
22. Juli, 20:36 As of July 16 Salesforce is no longer accepting the 'multipleauthn' as a valid MFA claim. We have an EntraID/DUO SSO setup as well and our users are now being prompted for additional MFA in the Salesforce UI. Has anyone figured out a way to get an approved claim passed back to Salesforce?
*** Important change for: All Core Org Admins & Security Contacts ***This update is limited to Salesforce Platform.
In Progress Enhancements: Immediate Action Required
Salesforce is enforcing these controls now. To avoid service disruption, verify your configuration.
- Email Domain Verification: Email domain verification is now required to send emails from Salesforce. Learn more about the change and the enforcement timeline.
- High-Risk Connection Blocking: Ensure that your users aren’t connecting to Salesforce via anonymizing VPNs, proxies, or high-risk IP addresses. Salesforce monitors for and blocks high-risk connections through Connected App or API usage and anomaly detection for login activity.
Upcoming Enhancements: Take Action Now
Detailed enforcement dates for each control are available in the linked resources.
- Phishing-Resistant Multi-Factor Authentication (MFA) for Privileged Users, including Admins: Phishing-resistant MFA will be enforced for System Administrators and users who have certain privileged permissions when they log in to any org, including sandboxes. This requirement applies to direct UI and Single Sign-On (SSO) logins. Learn more about how to set up this feature and the enforcement timeline.
- MFA for All: MFA will be enforced for all employee license users who log in via the Salesforce UI or Single Sign-On (SSO) to all orgs, including sandboxes. Learn more about how to set up this feature and the enforcement timeline.
- Step-Up Authentication: Salesforce will enforce identity verification challenges for all users (including those using SSO) when they perform high-sensitivity actions, starting with UI report exports and viewing, and for anomalous behavior while accessing reports. This change applies across all orgs, including sandboxes. To prepare for this change, ensure that your users each have one of the following registered: Salesforce MFA, a current email address, or a mobile phone number. To learn more about how to prepare for this change, see Prepare for the upcoming Step-up Authentication requirements on Report Actions and Prepare for Step-up Authentication in Anomalous Report Export.
- Upcoming Transaction Security Policy (TSP) Enhancements (Shield & Event Monitoring customers): Salesforce will automatically deploy a default TSP for ReportEvent. When enabled, this policy triggers a step-up authentication challenge for UI report exports that exceed 10,000 records. Additionally, a new "Manage Transaction Security Policy" permission will be required, in addition to the "Customize Application" permission, to manage any TSP. Review and assign this new permission to authorized users before enforcement. Learn more about how to set up this feature and the enforcement timeline.
Strongly Recommended but Not Required at This Time
This control is recommended but not mandatory as previously announced.
- IP Address Restriction: Salesforce isn’t enforcing the IP address restrictions in profiles or the “Enforce login IP ranges on every request” session setting at this time. However, we continue to strongly recommend that you adopt IP address restrictions and enable the setting, and we may require that configuration in the future. To learn more about how to configure your IP Allowlist permissions, see Restrict Login IP Addresses in Profiles and Set Trusted IP Ranges for Your Org.
- Phishing-Resistant MFA for Non-Admin Users: To ensure the highest level of protection against identity-based threats, Salesforce strongly recommends that you implement phishing-resistant MFA for all users. See Prepare for MFA Enforcement for All Employee Users.
More Information
Join one of these webinars where Salesforce experts will discuss these changes.
20. Juli, 14:47 Thank you @Mayur Mate & @Sai Srivatsav Dharini for your valuable feedback. Appreciate it!
With the waive MFA permission being phased out, what are customers expected to do when they bring on a third-party consulting partner to create projects and those users need System Admin privileges?
#MFA30. Juni, 15:45 Thank you for that information. Our company does approve/allow one of the password managers. However, I do not use it and am unsure the corporate thought on a shared service user. I will ask my manager about that possibility.
"Are you saying that in a "Login As" session, the service user's managed package license does not work?"
I would say that it does not *fully* work. We are able to access the package content and do some things, but not the things that we ultimately need this Service User to do:
- We give our Service User a license to use this managed package.
- I have a license to use this managed package.
- When logged in directly as myself, I can schedule jobs "inside" this managed package.
- When logged in directly as the Service User, I can schedule this managed package's jobs.
- When I login as myself, then use the Salesforce "Login As" functionality to login as the Service User, I am unable to schedule this managed package's jobs.
I am unsure whether this is across all managed packages or just this one. But I can say that this is either a feature of this managed package or a known bug that they have embraced as a "feature."
Currently I am testing whether a Service User can schedule and run these jobs without "privileged" access. If so, we could split our current Service User into two and have one non-privileged with "standard" MFA for the managed package.
*** Important Update: Step-Up Authentication for Report Actions ***Hey Trailblazers! We have some important updates to share about the upcoming Step-Up Authentication requirement for Report Actions — Here's what you need to know:
Change 1: Step-Up Challenges Now Scoped to Export Actions Only
Step-Up Authentication challenges will now trigger only when exporting or printing reports — not when simply viewing reports, dashboards, or accessing the Reports/Dashboards tabs in the UI.
The Session Level Policy setting has been added to reflect this:
"Require periodic step-up authentication when exporting or printing"
This updated policy replaces the prior setting upon enforcement. Find this by going to Setup -> Identity Verification and selecting the new policy for Reports and Dashboards.
Change 2: Profile Login IP Restrictions as an Alternate Control
Step-Up Authentication for report exports will not be required when both of the following conditions are met:
- A user's Profile has Login IP restrictions configured, AND
- Either the user's IP address hasn't changed between login and report export, or "Enforce login IP ranges on every request" is enabled in Session Settings
This gives admins a meaningful alternate control if your org uses IP-based access restrictions and when configured, users will not see step-up challenges during report export.
Enforcement Timeline — No Changes
Enforcement dates remain unchanged from what was previously published:
- All Sandboxes: June 17 – June 24
- Production: July 1 – July 25
Additional Resources
- Prepare for the upcoming Step-Up Authentication requirements on Report Actions (Updated June 16, 2026)
- Restrict Login IP Addresses in Profiles
Have questions? Drop them in the comments below — we're here to help!
29. Juni, 17:11 thanks for this information: "...in our testing, we have OKTA authentication for login but I currently have Salesforce authenticator as well so it kicks me there to verify the export."
I was
wondering whether Admins could respond to the report export challenges via the regular authenticator. To me, that seems easier than going back to the initial login method for Admins, which in our case might be Entra with a biometric option. Is this what others are seeing? (thanks, this has been very confusing for our small-ish org)