Skip to main content

#MFA - Getting Started토론 중인 항목 12개

FIX: “Problem Verifying Your Identity” after Salesforce MFA/passkey changes 

 

I wanted to share the solution to a frustrating Salesforce login problem in case it saves someone else a lot of troubleshooting.

I am the sole user/System Administrator of my Salesforce org. After the recent MFA/passkey changes, I began receiving this error when trying to log in:

“Problem Verifying Your Identity. To log in, you need both a higher access level and an identity verification method. Contact your administrator to gain login access.”

I already had Salesforce Authenticator and a registered passkey. The passkey worked on My Macbook laptop but I had inconsistent or failed logins on my iMac desktop. I tried different browsers, clearing cache, temporary verification codes, etc.

I eventually had a Google Meet with a Salesforce support technician. After I shared my screen, he spotted the problem almost immediately:

Lightning Login was still enabled on my user account.

The fix took about one minute:

Profile photo → Settings → My Personal Settings → Advanced User Details → scroll down to Lightning Login → Cancel

After canceling Lightning Login, I was immediately able to log into Salesforce normally using Google Chrome and my passkey.

For anyone encountering this specific error after the new phishing-resistant MFA/passkey rollout, I strongly recommend checking whether Lightning Login is still enabled before spending hours troubleshooting passkeys, browsers, MFA settings, or devices.

I hope this saves someone else the time it took me to find the solution.

#MFA - Getting Started

 

 

댓글 2개
  1. 8월 31일 오후 4:55

    I’m seeing similar behavior. We use Azure Active Directory SSO, but after users click “Log in using Azure Active Directory,” Salesforce redirects them to its Create a Passkey screen and pushes additional Salesforce authentication/verification setup. 

    Using a Microsoft Authenticator one off password gets the user in, but the Salesforce passkey prompt returns. That’s the issue I’m trying to resolve... users are authenticating through our SSO provider, yet Salesforce is still inserting its own enrollment/verification flow.

0/9000

Last week, I created a passkey for my Sandbox org and was able to log in without any problems for several days.

Today, after not logging in over the weekend, I was unable to authenticate beyond the screen below. Every time I clicked the "Verify Your Identity" button, the page simply reloaded.

  

 

Having problems authenticating whit MFA

 

I asked another System Administrator for help, and they deleted the

Security Key (U2F/WebAuthn)

associated with my account. Now I'm stuck on the screen below and I'm unable to register a new passkey. The same issue is occurring: whenever I click the button, the page simply reloads.  

 

image.png

 

Is anyone having the same problem? I tried this at two different browsers and the same error occured. 

 

답변 8개
  1. 8월 25일 오후 10:02

    FIX: “Problem Verifying Your Identity” after Salesforce MFA/passkey changes

    I wanted to share the solution to a frustrating Salesforce login problem in case it saves someone else a lot of troubleshooting.

    I am the sole user/System Administrator of my Salesforce org. After the recent MFA/passkey changes, I began receiving this error when trying to log in:

    “Problem Verifying Your Identity. To log in, you need both a higher access level and an identity verification method. Contact your administrator to gain login access.”

    I already had Salesforce Authenticator and a registered passkey. The passkey worked on one computer but I had inconsistent or failed logins on another. I tried different browsers, clearing cache, temporary verification codes, etc.

    I eventually had a Google Meet with a Salesforce support technician. After I shared my screen, he spotted the problem almost immediately:

    Lightning Login was still enabled on my user account.

    The fix took about one minute:

    Profile photo → Settings → My Personal Settings → Advanced User Details → scroll down to Lightning Login → Cancel

    After canceling Lightning Login, I was immediately able to log into Salesforce normally using Google Chrome and my passkey.

    For anyone encountering this specific error after the new phishing-resistant MFA/passkey rollout, I strongly recommend checking whether Lightning Login is still enabled before spending hours troubleshooting passkeys, browsers, MFA settings, or devices.

    I hope this saves someone else the time it took me to find the solution.

    #MFA - Getting Started

0/9000

When our automation scripts are executed in Azure devops, they are failing because of verification code. In my local machine I was able to bypass verification code step by adding my local IP in Salesforce network access settings. I am aware that we can disable it at profile level but I am looking for a solution to disable verification code at user level. Please suggest what could be the best approach here.

답변 10개
  1. Mohit Kumar Agarwal (Dell Technologies) Forum Ambassador
    2022년 3월 12일 오전 10:14

    Understand. Lets try this, Try taking the IP addresses from the Administer > Manage Users > Login History for that user and then try that particular range to bypass. If IP ranges are not that too dynamic that it should work OR else try to reach salesforce support team and see if they can do anything for you

0/9000

Hello,

 

Today i accidently uninstalled authenticator app and i don't have any backup also to recover.

 

Now i am not able to login into https://anypoint.mulesoft.com/. MFA verification code is required to login.

 

Any help on this issue. Thanks in advance

MFA - Microsoft Authenticator App Uninstalled ?

답변 6개
0/9000
Erika Nelson Fish 님이 * MFA - Getting Started *에 질문했습니다

Hi - In our Sandbox (running Summer '22) Session Settings there is an info pop-up that references the user permission "Waive MFA for exempt users". It sounds like a good idea to assign to our External Identity users to ensure that MFA isn't required when Salesforce eventually enforces MFA globally. (Note: I do understand that MFA is not required for external users, I just want to be extra cautious.)

 

Does anyone know where this "Waive MFA" permission is? I assume it's Summer '22, but I can't find it in our Sandbox where I expected in either Sessions Settings or in Permission Sets-->System Permissions. Thank you!

Where is

답변 16개
  1. 2022년 6월 13일 오후 4:20

    Good news: Our production was upgraded to Summer '22 over the weekend and I now see "Waive MFA for Exempt Users" as an option in the System Permissions of Permission Sets! 

     

    I asked the question initially because I didn't see this in the Sandbox Summer '22 upgrade. Looks like it's GA for production now. Thanks for the responses, Mohit! 

0/9000

How to allow Admin users to bypass SSO to log in directly to Salesforce with a username and password

Hi, we have set up SSO/MFA on our Org, using Azure AD as our Identity provider. Doing this has removed the native Salesforce login for all users.  BUT we want to allow for Admin users to bypass SSO and have the option to log in directly to Salesforce with a username and password in case of a problem with SSO login and for other Admin tasks like Sandbox set up and maintenance.  Any help or tips on how to allow for this kind of setup?  Azure SSO works fine but when attempting to browse to the URL - http://login.salesforce.com/ we are not able to login with our usual SysAdmin username and password.    The suggested solution in MyDomain settings to "Keep 'Login Policy' unchecked "  seems to me to be an insecure workaround rather than a stable and secure solution for allowing the option of a separate local Salesforce login for our Admin users?    Do Salesforce have any official guidelines for a separate local logon in an enforced / compliant SSO-MFA environment?  Seems a major omission if not? 

답변 11개
  1. 2022년 1월 15일 오후 10:31

    @Amnon Kruvi unless the “Is Single Sign-On Enabled" permission is given either at the profile level or via permission set, users can still choose between regular login and SSO on the login page (assuming both login forms are marked as available). In our case, we gave everyone the permission at the profile level except system admins, who will log in with credentials and the Authenticator app for MFA.

    Users who attempt to log in via credentials will just receive an error message, and since we use SSO they can't reset their passwords either. 

0/9000

We are using Microsoft Authenticator. One of my users followed the prompts and scanned the QR code but then for some reason, it's not showing up. It worked the very first time she used it but then didn't the second/future attempts. How can she go back to access the QR code to get it set up properly? 

답변 8개
  1. 2022년 1월 27일 오전 12:05

    They will still need the permission set assigned. I found the Salesforce help article that list the steps so hopefully this will work. 

     

    https://help.salesforce.com/s/articleView?id=sf.disconnect_salesforce_authenticator_v2_or_later.htm&type=5

     

    Since you are using Microsoft authenticator you will follow the same steps as above, just the last part is you will click disconnect on the option that says "App Registration: One-Time Password Authenticator"

0/9000

I've implemented MFA in our Sandbox using the Salesforce Authenticator app and have everything setup for myself to test.  When I attempt to login to Salesforce I get the message "Use Salesforce Authenticator to approve the request to Log In to Salesforce." stating they've pushed the notification for me to Approve/Deny it to my phone.  However, I never seem to get those push notifications.  I always have to click Having Trouble and using other verification methods for logging in and use the code from the authenticator app.  After doing that I'm able to get in.  Has anyone else been experiencing this issue?  Thanks

답변 15개
  1. 2025년 11월 7일 오전 11:31

    I was also facing the same issue. I did checked following  

    Mobile phone settings for the notifications for the salesforce authenticator app. 

    Internet connection should be stable or else you will recieve the notification after a certain time delay. 

    Keep refreshing the Authenticator app when you send for approval. 

     

    It did not worked instantly but after some time It started working. But sometimes there is no other way but to use the security key. 

     

     

0/9000

Hi, we have implemented SSO / MFA using Okta and all SF users have downloaded the Okta verify app.  One user (in addition to me, the admin) has access to Dataloader but they can't log in to it since we set up MFA.  She keeps getting the 'invalid password' error, even though the correct password is being used. We've tried adding the security token to the end of the password, clearing cookies and cache, uninstalling and reinstalling Dataloader and switching her to use the SF verification app instead of Okta. Nothing works, the login history just keeps returning 'invalid password'.

 

It feels like we are stuck in a loop and I don't know how to break it. I can use Dataloader fine so we know it SHOULD work, it just doesn't.

 

Has anyone got any suggestions of things we can try?

답변 4개
  1. 2025년 8월 1일 오후 12:39

     In my case MFA was enabled so below worked for me: 

    1. Grant " Multi-Factor Authentication for API Logins" permission to profile. 

    2. Use Password Authentication instead of OAuth option.  

    3. Enter "password + single-use code" in the password field (single-use code: 6-digit number displayed in the app). 

     

    Reference here 

0/9000

One of our vendors, who has had "Account Login Access" for the past few weeks is unable to login this morning with the following error:

 

Can't Log In to Subscriber Org

Multi-factor authentication (MFA) is required to log into subscriber orgs from the Subscriber Support Console. To request permission to access the Subscriber Support Console, or to set up MFA for your License Management Org (LMO), contact your salesforce admin.

 

My user currently has the permission set for Multi-Factor Authentication for User Interface Logins.

답변 7개
  1. 2025년 7월 12일 오후 10:56

    I was signed in with SSO and the following steps worked for me.  

     

    1. Change or reset password. 
    2. Delete cookies
    3. Logout and when logging back in, click login with a different account.
    4. Enter email as username and newly created password.
    5. There should now be a screen asking to register the account with the Salesforce Authenticator app. Follow the steps to setup Salesforce Authenticator for the account.
    6. After the app redirects to be logged back in. Log out again.
    7. Login again using username/password instead of SSO. MFA through Salesforce Authenticator should be required to finish login.
0/9000