Skip to main content

#MFA - Getting Started1 discussing

When our automation scripts are executed in Azure devops, they are failing because of verification code. In my local machine I was able to bypass verification code step by adding my local IP in Salesforce network access settings. I am aware that we can disable it at profile level but I am looking for a solution to disable verification code at user level. Please suggest what could be the best approach here.

9 answers
  1. Mohit Kumar Agarwal (Dell Technologies) Forum Ambassador
    Mar 12, 2022, 10:14 AM

    Understand. Lets try this, Try taking the IP addresses from the Administer > Manage Users > Login History for that user and then try that particular range to bypass. If IP ranges are not that too dynamic that it should work OR else try to reach salesforce support team and see if they can do anything for you

0/9000

Hi - In our Sandbox (running Summer '22) Session Settings there is an info pop-up that references the user permission "Waive MFA for exempt users". It sounds like a good idea to assign to our External Identity users to ensure that MFA isn't required when Salesforce eventually enforces MFA globally. (Note: I do understand that MFA is not required for external users, I just want to be extra cautious.)

 

Does anyone know where this "Waive MFA" permission is? I assume it's Summer '22, but I can't find it in our Sandbox where I expected in either Sessions Settings or in Permission Sets-->System Permissions. Thank you!

Where is

16 answers
  1. Jun 13, 2022, 4:20 PM

    Good news: Our production was upgraded to Summer '22 over the weekend and I now see "Waive MFA for Exempt Users" as an option in the System Permissions of Permission Sets! 

     

    I asked the question initially because I didn't see this in the Sandbox Summer '22 upgrade. Looks like it's GA for production now. Thanks for the responses, Mohit! 

0/9000

How to allow Admin users to bypass SSO to log in directly to Salesforce with a username and password

Hi, we have set up SSO/MFA on our Org, using Azure AD as our Identity provider. Doing this has removed the native Salesforce login for all users.  BUT we want to allow for Admin users to bypass SSO and have the option to log in directly to Salesforce with a username and password in case of a problem with SSO login and for other Admin tasks like Sandbox set up and maintenance.  Any help or tips on how to allow for this kind of setup?  Azure SSO works fine but when attempting to browse to the URL - http://login.salesforce.com/ we are not able to login with our usual SysAdmin username and password.    The suggested solution in MyDomain settings to "Keep 'Login Policy' unchecked "  seems to me to be an insecure workaround rather than a stable and secure solution for allowing the option of a separate local Salesforce login for our Admin users?    Do Salesforce have any official guidelines for a separate local logon in an enforced / compliant SSO-MFA environment?  Seems a major omission if not? 

11 answers
  1. Jan 15, 2022, 10:31 PM

    @Amnon Kruvi unless the “Is Single Sign-On Enabled" permission is given either at the profile level or via permission set, users can still choose between regular login and SSO on the login page (assuming both login forms are marked as available). In our case, we gave everyone the permission at the profile level except system admins, who will log in with credentials and the Authenticator app for MFA.

    Users who attempt to log in via credentials will just receive an error message, and since we use SSO they can't reset their passwords either. 

0/9000

We are using Microsoft Authenticator. One of my users followed the prompts and scanned the QR code but then for some reason, it's not showing up. It worked the very first time she used it but then didn't the second/future attempts. How can she go back to access the QR code to get it set up properly? 

8 answers
  1. Jan 27, 2022, 12:05 AM

    They will still need the permission set assigned. I found the Salesforce help article that list the steps so hopefully this will work. 

     

    https://help.salesforce.com/s/articleView?id=sf.disconnect_salesforce_authenticator_v2_or_later.htm&type=5

     

    Since you are using Microsoft authenticator you will follow the same steps as above, just the last part is you will click disconnect on the option that says "App Registration: One-Time Password Authenticator"

0/9000

I've implemented MFA in our Sandbox using the Salesforce Authenticator app and have everything setup for myself to test.  When I attempt to login to Salesforce I get the message "Use Salesforce Authenticator to approve the request to Log In to Salesforce." stating they've pushed the notification for me to Approve/Deny it to my phone.  However, I never seem to get those push notifications.  I always have to click Having Trouble and using other verification methods for logging in and use the code from the authenticator app.  After doing that I'm able to get in.  Has anyone else been experiencing this issue?  Thanks

15 answers
  1. Nov 7, 2025, 11:31 AM

    I was also facing the same issue. I did checked following  

    Mobile phone settings for the notifications for the salesforce authenticator app. 

    Internet connection should be stable or else you will recieve the notification after a certain time delay. 

    Keep refreshing the Authenticator app when you send for approval. 

     

    It did not worked instantly but after some time It started working. But sometimes there is no other way but to use the security key. 

     

     

0/9000

Hi, we have implemented SSO / MFA using Okta and all SF users have downloaded the Okta verify app.  One user (in addition to me, the admin) has access to Dataloader but they can't log in to it since we set up MFA.  She keeps getting the 'invalid password' error, even though the correct password is being used. We've tried adding the security token to the end of the password, clearing cookies and cache, uninstalling and reinstalling Dataloader and switching her to use the SF verification app instead of Okta. Nothing works, the login history just keeps returning 'invalid password'.

 

It feels like we are stuck in a loop and I don't know how to break it. I can use Dataloader fine so we know it SHOULD work, it just doesn't.

 

Has anyone got any suggestions of things we can try?

4 answers
  1. Aug 1, 2025, 12:39 PM

     In my case MFA was enabled so below worked for me: 

    1. Grant " Multi-Factor Authentication for API Logins" permission to profile. 

    2. Use Password Authentication instead of OAuth option.  

    3. Enter "password + single-use code" in the password field (single-use code: 6-digit number displayed in the app). 

     

    Reference here 

0/9000

One of our vendors, who has had "Account Login Access" for the past few weeks is unable to login this morning with the following error:

 

Can't Log In to Subscriber Org

Multi-factor authentication (MFA) is required to log into subscriber orgs from the Subscriber Support Console. To request permission to access the Subscriber Support Console, or to set up MFA for your License Management Org (LMO), contact your salesforce admin.

 

My user currently has the permission set for Multi-Factor Authentication for User Interface Logins.

7 answers
  1. Jul 12, 2025, 10:56 PM

    I was signed in with SSO and the following steps worked for me.  

     

    1. Change or reset password. 
    2. Delete cookies
    3. Logout and when logging back in, click login with a different account.
    4. Enter email as username and newly created password.
    5. There should now be a screen asking to register the account with the Salesforce Authenticator app. Follow the steps to setup Salesforce Authenticator for the account.
    6. After the app redirects to be logged back in. Log out again.
    7. Login again using username/password instead of SSO. MFA through Salesforce Authenticator should be required to finish login.
0/9000

Kennt jemand eine Lösung, wie Salesforce User (Innendienst) die kein mobil-Phone haben, eingerichtet werden müssen, damit MFA erfüllt wird? Bislang habe ich keine kostenlose, aktzeptierte Lösung seitens Salesforce erhalten.

9 answers
  1. Heiko Lindner (Privat) Forum Ambassador
    Apr 16, 2025, 12:46 PM

    Es gibt auch Erweiterungen für den Browser - bspw. 2FAS oder hier  ob dies zuverlässig funktionieren, kann ich nicht sagen/ beurteilen. Aber ist eine Option

0/9000

I need the Metadata for my Salesforce Org (Sandbox for Testing, then Productive) to setup Single Sign-On.

The Description here:

https://help.salesforce.com/s/articleView?id=sf.identity_provider_examples_3p_adfs.htm&type=5

says in the section "Configure Salesforce" :

"Salesforce metadata is downloaded as an XML file that AD FS 2.0 can consume."

However, I find no way to download the metadata file in the saleforce setup.

Under "SAML Single Sign-On Settings" I find the option to import a metadata file, but nowhere a way to export the salesforce metadata.

Any hint how this can be done is highly appreciated.

4 answers
  1. Feb 12, 2025, 12:48 PM

    I've automated this process with a Bash script that uses the Salesforce CLI and 'jq'.  It lists all metadata types, retrieves them individually, and reports the total execution time. This can be useful for backup purposes, deployments, or simply understanding your org's configuration. The script is hosted on GitHub

    . Any feedback on how to improve this would be greatly appreciated! 

     

    GitHub Link:

    https://github.com/falgun-panara/Salesforce-Metadata-Retrieval-Script/

0/9000

A user accidentally removed their Salesforce account from Authenticator. They deleted the app and reinstalled it. After initial set-up (phone number and text, passcode setup) they tried logging in to Salesforce and saw this screen. After clicking on Use a Different Verification Method, selecting the Approve using Salesforce Authenticator option leads them back to the screen below. Selecting the "Use a code from an authenticator app" option didn't seem to help, as the 2-word phrase from Authenticator set-up doesn't work in this step and there's no clear way to generate another type of code from Authenticator.

 

Our Salesforce architect found a temporary solution by turning off MFA for this user and somehow generating a code they could use upon login. But we need to find a way to have this user reconnect their Salesforce account to Authenticator and continue using MFA upon login, as all users in our organization are required to. What should we do?

User removed their account from Authenticator, cannot reconnect

4 answers
  1. Jan 14, 2025, 2:17 PM

    Hi @Josh Millhouse,

    In my case my id is removed accidentally from salesforce authenticator and now it is asking while login the code from authenticator app. As I am unable to logged into org how to proceed in this case,

0/9000