Skip to main content
Viesna Tร‰ ๋‹˜์ด #MFA์— ์งˆ๋ฌธํ–ˆ์Šต๋‹ˆ๋‹ค

Hi everyone,

I have an issue with 3 new users in our Salesforce org.

They replaced former employees, and I reused the former employees' Salesforce User records instead of creating new Users. I changed the name and username.

The users are Active and not Frozen, but they cannot complete the login process normally.

As an admin, I can generate a Temporary Verification Code. They can log in with it and reach the QR code screen to set up MFA, but Iโ€™m wondering if the previous user's MFA/verification method could still be linked to the User record.

Is there an official way to disconnect the previous user's MFA/verification method and register a new one for the new user?

Also, could this be related to any Summer โ€™26 MFA/authentication changes?

Would it be better practice to deactivate the old User and create a completely new User for each new employee?

Thanks for any advice!

And sorry for my English โ€” Iโ€™m French ๐Ÿ˜Š 

 

#MFA

๋‹ต๋ณ€ 5๊ฐœ
  1. 9์›” 11์ผ ์˜คํ›„ 3:31

    @Viesna Tร‰

     

     

    That's actually good news - if nothing is registered, there's no leftover method from the previous employee sitting on those records, so your original concern is cleared and the Disconnect step just doesn't apply to your case. 

     

    The QR screen you're reaching IS the resolution: have each user finish enrolling their own method there (scan the code in Salesforce Authenticator or any TOTP app and confirm). After that one-time enrolment they'll log in normally and won't need a temporary code again. 

     

    If a user still can't complete login even after enrolling, check the Email field on that reused record - identity-verification codes are sent to that address, so if it's still the former employee's email the new person never receives the code and you're forced to keep issuing temporary ones. Setting it to the new person's real email usually clears that last blocker.

0/9000