Hi everyone,
I’m experiencing a persistent WebAuthn loop during MFA setup in one specific Salesforce organization, and I’d really appreciate the community’s technical insight into what could be causing the discrepancy.
I have two independent Salesforce environments running on the same Windows 11 laptop and using the same browsers (Chrome/Edge).
Org A
Everything works as expected:
- When I go to Advanced User Details → Built-In Authenticators → Add, Windows Security displays the native “Sign in with a passkey” prompt.
- It correctly recognizes the credential for my Salesforce user.
- The credential is associated with the expected Salesforce domain
- I can authenticate immediately using my local Windows Hello PIN.
Org B
The behavior is completely different:
- Under Advanced User Details → Built-In Authenticators → Add, Windows Security does not offer the local “This Device” / Windows Hello platform authenticator.
- Instead, it immediately launches the roaming/cross-platform authenticator flow and displays the Mobile Phone / QR-code prompt.
- Selecting “Choose a different passkey” or “Save another way” does not expose Windows Hello; it simply returns me to the same QR-code flow.
- As a result, I am effectively stuck in an unskippable WebAuthn registration loop.
Settings already verified in Org B
I have checked the relevant Salesforce configuration and cannot identify an obvious organizational restriction:
- Identity Verification Settings “Let users verify their identity with a built-in authenticator (passkey) such as Touch ID or Windows Hello” is explicitly enabled.
- Session Security Level Policies Administrative operations, including Profile and Permission Set management, are configured with None for High Assurance session step-up requirements.
- Browser extensions The Microsoft Authenticator extension is enabled in both environments, so extension differences do not appear to explain the behavior.
I would appreciate any suggestion as I am running in loops and have always to use my iphone to scan a QR Code because Salesforce is asking me for a passkey. I can not use my PIN in Windows Hello.
@Salesforce Administrators & Developers, @Salesforce Administrators and Developers, @APAC Architects
#Trailhead #Salesforce Developer #Salesforce Admin #TrailblazerCommunity
Hi @Lena Wong
Since Windows Hello works in Org A on the same device and browser, but Org B redirects to the QR-code flow, I recommend:
- Clear Salesforce site data and retry using Chrome/Edge.
- Check Windows Settings → Accounts → Passkeys to ensure Windows Hello is available.
- Compare the authentication and SSO configuration between both orgs.
- Test with a fresh browser profile or another supported browser.
If the issue persists, check Salesforce Known Issues or contact Salesforce Support with the Org B details.
Hope This Helps!!