Skip to main content
Lena Wong preguntó en #Trailhead

Hi everyone,

I’m experiencing a persistent WebAuthn loop during MFA setup in one specific Salesforce organization, and I’d really appreciate the community’s technical insight into what could be causing the discrepancy.

 

I have two independent Salesforce environments running on the same Windows 11 laptop and using the same browsers (Chrome/Edge). 

 

Org A 

Everything works as expected:

  • When I go to Advanced User Details → Built-In Authenticators → Add, Windows Security displays the native “Sign in with a passkey” prompt.
  • It correctly recognizes the credential for my Salesforce user.
  • The credential is associated with the expected Salesforce domain 
  • I can authenticate immediately using my local Windows Hello PIN.

Org B 

The behavior is completely different:

  • Under Advanced User Details → Built-In Authenticators → Add, Windows Security does not offer the local “This Device” / Windows Hello platform authenticator.
  • Instead, it immediately launches the roaming/cross-platform authenticator flow and displays the Mobile Phone / QR-code prompt.
  • Selecting “Choose a different passkey” or “Save another way” does not expose Windows Hello; it simply returns me to the same QR-code flow.
  • As a result, I am effectively stuck in an unskippable WebAuthn registration loop.

Settings already verified in Org B

I have checked the relevant Salesforce configuration and cannot identify an obvious organizational restriction:

  1. Identity Verification Settings 

    “Let users verify their identity with a built-in authenticator (passkey) such as Touch ID or Windows Hello” is explicitly enabled.
  2. Session Security Level Policies 

    Administrative operations, including Profile and Permission Set management, are configured with

    None for High Assurance session step-up requirements.
  3. Browser extensions 

    The Microsoft Authenticator extension is enabled in both environments, so extension differences do not appear to explain the behavior.

I would appreciate any suggestion as I am running in loops and have always to use my iphone to scan a QR Code because Salesforce is asking me for a passkey. I can not use my PIN in Windows Hello. 

 

@Salesforce Administrators & Developers, @Salesforce Administrators and Developers, @APAC Architects

 

 

#Trailhead  #Salesforce Developer  #Salesforce Admin  #TrailblazerCommunity

2 respuestas
  1. Ayer, 17:28

    Hi @Lena Wong

     

     Since Windows Hello works in Org A on the same device and browser, but Org B redirects to the QR-code flow, I recommend:

    1. Clear Salesforce site data and retry using Chrome/Edge.
    2. Check Windows Settings → Accounts → Passkeys to ensure Windows Hello is available.
    3. Compare the authentication and SSO configuration between both orgs.
    4. Test with a fresh browser profile or another supported browser.

    If the issue persists, check Salesforce Known Issues or contact Salesforce Support with the Org B details.  

     

    Hope This Helps!!

0/9000