Skip to main content

Hi everyone,   

I have a question regarding the upcoming MFA enforcement for all employee users.   

Let's consider this scenario:

If organization has five administrators who all use the same System Administrator username and password (shared login). The email address associated with that Salesforce user belongs to me.

When Salesforce prompts us to register a Passkey, I complete the registration using my device because the email is mine. After that, when another administrator tries to log in using the same shared credentials, Salesforce requires the registered passkey, which only I have. As a result, the other admins are unable to log in.    How should organizations handle this situation?

  • Is sharing one System Administrator account no longer supported with passkeys?
  • Does Salesforce expect every administrator to have their own individual user account?
  • If a shared admin account must be used (for legacy reasons), what is the recommended approach to satisfy the new MFA/passkey requirement?

I'd appreciate any guidance or best practices from the community. Thanks!    

1 answer
  1. Jul 13, 1:48 PM

    @Sourabh Dondekar, shared admin logins are not the right approach anymore, especially with MFA/passkeys. Each admin should have their own named Salesforce user account, with their own MFA method or passkey. This is also important for audit history, setup changes, login tracking, and accountability.

    A passkey is tied to the user/device that registers it, so if five people share one admin login, the others can get blocked when Salesforce asks for that passkey. 

     

    Kindly check this for reference: https://help.salesforce.com/s/articleView?id=xcloud.mfa_supported_verification_methods_bia.htm&type=5

0/9000