Based on the SF announcement that come June, System Administrator users need to adopt Phishing-Resistant MFA for login, we will move to using a Yubikey for me. We are a relatively small non-profit, totally virtual/no physical location. Thus, all workers are remote. We have 20 SF users. I appreciate any guidance. Question is, what is the justification or real world need for use making it required for all our users to use a physical key?
I wanted to share with everyone some quick updates on this. The enhanced MFA requirements have gone live in my Sandbox and just so everyone knows the UI has changed a bit. I am posting a couple of screen shots, as an fyi.
Also, if you now hit "Use a Different Verification Method", it takes you to this screen.
Not a huge deal, but if you have created any training documents around this, you may need to update them.