Based on the SF announcement that come June, System Administrator users need to adopt Phishing-Resistant MFA for login, we will move to using a Yubikey for me. We are a relatively small non-profit, totally virtual/no physical location. Thus, all workers are remote. We have 20 SF users. I appreciate any guidance. Question is, what is the justification or real world need for use making it required for all our users to use a physical key?
Good question @Heath Parks
. Because authentication methods don't carry over from production, you do need to reset up sandbox every time you create new or refresh an existing sandbox (i.e. delete whatever passkey you have saved and re-create a new one, if you're using a password manager). We run into this now when someone refreshes a sandbox, but there's an old TOTP code saved in the existing password vault and they don't update it when they sign into the refreshed sandbox.
I wonder if that will change, however. For instance, I know SSO doesn't get carried over for legitimate reasons, like dKIM doesn't carry over. But will MFA in the future?