We have OKTA enabled SSO ( ID Initiated) for our Salesforce Production org only. We are planning to implement for our non prod org. For user experience, we are getting push notification through OKTA and then user able to login in to Salesforce. As SSO was implemented long back, we want to know with upcoming security checks ( June 2026) our current configuration is compliant. What is best way to verify ?
Since we are using OKTA SSO with push-based MFA, Salesforce MFA compliance depends on whether the MFA challenge is enforced at the IdP and correctly passed in the SAML assertion. The best way to verify is by checking Login History for the “Authentication Method Reference” field showing “mfa”. Additionally, validate OKTA sign-on policies to ensure MFA is enforced for all users and not bypassed. We should also test in non-production orgs and use Salesforce’s MFA Assistant to confirm compliance ahead of the June 2026 security checks
If it works for you, feel free to mark it as the best answer.