Skip to content

Salesforce Passkey MFA: Summer '26 Admin Troubleshooting Guide

Salesforce now enforces passkey MFA for privileged users and MFA for all employees. Learn who is affected, mobile fixes, and the extension to request.

Salesforce Passkey MFA: Summer '26 Admin Troubleshooting Guide
Salesforce Passkey MFA: Summer '26 Admin Troubleshooting Guide

If users in your org suddenly started seeing passkey prompts after July 1, 2026, you are not looking at a misconfiguration — you are looking at a platform-enforced change. With the Summer '26 release (v262), Salesforce began enforcing MFA for all employee users and phishing-resistant MFA for privileged users, with passkeys as the default first option in MFA registration.

This guide covers what changed, who is forced into passkeys, why mobile "Verify Identity" does nothing, and the admin actions — including a Salesforce-supported extension request — that reduce friction without weakening security. It is the operational companion to our Salesforce security overhaul preparation guide.

Quick Answer

What changed? Effective July 1, 2026, Salesforce enforces MFA for all employee users and phishing-resistant MFA (passkeys or security keys) for privileged users, with passkey-first registration for direct logins.

Who is affected? Every org with direct UI logins. Users with the System Administrator profile (or a clone), Modify All Data, View All Data, Customize Application, or Author Apex must use a passkey; Authenticator and TOTP apps no longer qualify for them.

Is it a bug? Mostly no. Desktop passkey prompts are expected platform behavior; the mobile app's dead "Verify Identity" button is a confirmed product limitation with workarounds.

What should admins do? Audit privileged permissions, fix mobile (app v262.010+, native browser authentication), and — if needed — ask Salesforce for the temporary PRMFA (Passkeys) Extension, which keeps MFA fully enforced while deferring passkeys.

TL;DR

  • Passkey MFA is now enforced, not optional. Summer '26 (v262) mandates MFA for all employee users and phishing-resistant MFA for privileged users, effective July 1, 2026.
  • Passkeys are shown first by design. Salesforce auto-enabled passkey methods and auto-disabled the "show all methods" registration option.
  • Privileged users have no alternative. "Choose Another Verification Method" is removed; only a passkey or SSO with accepted AMR/ACR signals satisfies the requirement.
  • Mobile has a known dead-end. The mobile app's embedded WebView cannot trigger passkey prompts; update to v262.010+ and use native browser authentication.
  • Relief exists. Salesforce grants temporary extensions on request — the PRMFA (Passkeys) Extension defers passkeys while keeping MFA fully enforced.

What Changed: Salesforce's Summer '26 MFA Enforcement

With Summer '26, Salesforce flipped three enforcement switches at the platform level, effective July 1, 2026 — which is why the prompts appeared almost overnight:

  1. MFA is enforced for all employee users. The org-wide "Require MFA for all direct UI logins" setting is force-enabled and greyed out; admins cannot disable it without a Salesforce-granted extension.
  2. Phishing-resistant MFA (PRMFA) is enforced for privileged users. They must verify with a passkey — a built-in authenticator such as Touch ID, Face ID, or Windows Hello, or a physical security key. TOTP apps and Salesforce Authenticator do not qualify.
  3. MFA registration is passkey-first for direct username/password logins.

Salesforce also changed three Setup → Identity Verification settings with no admin action:

  • Built-in authenticator (passkey) verification — automatically enabled.
  • Physical security key (passkey) verification — automatically enabled.
  • "Show all permitted verification method options for MFA registration" — automatically disabled, which is why registration opens on passkeys.

None of this is caused by anything in your org, and there is no Setup off-switch — Salesforce presents passkeys first deliberately because they are its most phishing-resistant method.

Which Users Must Use Passkeys?

Whether a user can pick a different MFA method depends entirely on their permissions, not their role or license.

Privileged users — passkey required, no alternative. Anyone with the System Administrator profile (or a clone), or the Modify All Data, View All Data, Customize Application, or Author Apex permission, is held to phishing-resistant MFA. "Choose Another Verification Method" is removed for these users; only a passkey — or SSO transmitting an accepted phishing-resistant AMR/ACR signal — satisfies the requirement.

Non-privileged users — passkey-first, but choice remains. Everyone else can click "Choose Another Verification Method" and register Salesforce Authenticator or a TOTP app, which satisfies standard MFA. Passkeys stay first by design, and even compliant users keep seeing the nudge — expected behavior, not an error.

Note: "Waive Multi-Factor Authentication for Exempt Users" no longer exempts anyone post-enforcement without a Salesforce-approved extension.

Why "Verify Identity" Does Nothing in the Salesforce Mobile App

This is a confirmed known product limitation. The standard mobile app authenticates through an embedded WebView that cannot invoke the FIDO2/WebAuthn passkey authenticator. When a privileged user taps "Verify Identity," the button fires a WebAuthn call the WebView cannot fulfill — no navigation, no prompt, no error. It primarily blocks privileged users.

Supported fixes:

  • Update the app to v262.010 or later, then use gear → "Login for Admin," which routes login through the system browser where the passkey prompt works.
  • Or enable "Use the native browser for user authentication" under Setup → My Domain → Authentication Configuration, then log in via "Login with Email." Users must fully log out and restart the app afterward — the authentication flow is cached.
  • Register the right kind of passkey. Passkeys are device-bound: mobile login requires a native iOS or Android biometric passkey registered from the phone's own browser. Desktop and cross-device QR-code passkeys will not work on mobile.

Edge cases:

  • One built-in-authenticator slot by default: registering Face ID on a phone can overwrite a desktop passkey (both can coexist if re-registered).
  • Security Keys ON while Built-in Authenticators are OFF can cause silent timeouts.
  • Mobile SDK 13.2.0 and earlier cannot support PRMFA; Intune-managed Edge is not supported.
  • Since July 2026, mobile login shows username first, then passkey or password — this can break UI test automation built on the old flow.

What to Do: The Admin Action Checklist

Work these five actions in order; the first has the highest impact.

  1. Audit privileged permissions. Across profiles and permission sets, remove System Administrator profile assignments, Modify All Data, View All Data, Customize Application, and Author Apex wherever they are not genuinely required. Every user removed exits the forced-passkey flow — over-provisioned permissions are the biggest amplifier of passkey friction, and this audit is fully within your control.
  2. Fix mobile now. Push the app update to v262.010+, enable native browser authentication under My Domain → Authentication Configuration, and have affected users register a device-native biometric passkey from the phone's browser, then restart the app.
  3. Request the PRMFA (Passkeys) Extension if you need temporary relief for privileged users (details below). Reference KB 005388907 in the case, and mention Known Issue W-23493728 if SSO is involved.
  4. Complete one-time compliant registrations. Have remaining non-privileged users register Salesforce Authenticator or a TOTP app via "Choose Another Verification Method," and re-enable "Show all permitted verification method options for MFA registration" if editable in your org.
  5. Reduce day-to-day friction. Roll out synced passkeys via a password manager, evaluate passwordless login, and review Session Security Level mappings if users are re-challenged during the day.

How to Reduce Passkey Friction Without Weakening Security

Counterintuitively, the fastest path to fewer clicks is leaning into passkeys rather than around them — once registered, a passkey is a single-step, phishing-resistant login:

  • Synced passkeys via a password manager. Salesforce's June 2026 guidance confirms cloud-synced tools such as 1Password, Bitwarden, and iCloud Keychain, so one passkey works across every device. Have each user register a backup passkey.
  • Consider "Allow passwordless login with passkeys." Registered users skip the password and code screens entirely. Confirm its state first — enabled unintentionally, it creates unexpected prompts.
  • Complete one compliant registration per user so the prompt stops blocking each login.
  • Separate step-up challenges from login. Step-up authentication (viewing or exporting reports) fires once per grace window — 120 minutes by default — separately from login. Review Session Security Levels so a completed MFA login raises the session to High Assurance and avoids duplicate challenges.
  • Shrink the privileged population so only users who genuinely need elevated permissions are held to the passkey-only standard.

Salesforce-Supported Relief: Temporary Extensions

Salesforce grants temporary extensions on request; ask Salesforce Support or your account executive:

  • Phishing-Resistant MFA (Passkeys) Extension — the recommended ask. Org-wide MFA stays enabled; privileged users are temporarily held to standard MFA and regain "Choose Another Verification Method." MFA remains fully enforced; only the passkey requirement is deferred.
  • MFA For All Employees Extension — unlocks the greyed-out org-wide toggle. Turning it off stops platform-enforced MFA entirely — the lowest security posture, not recommended.
  • "AdminPasskeysOptOut" — for admins who cannot surface a passkey prompt and have no other working login path.

How each configuration plays out for direct UI logins:

Configuration Non-Privileged Users Privileged Users (incl. Admins)
Default — no extensions (org-wide MFA locked ON) Standard MFA required (passkey-first registration; other methods selectable) PRMFA required — passkey only, no alternative
PRMFA (Passkeys) Extension only — org-wide MFA ON Standard MFA required Standard MFA required — "Choose Another Verification Method" restored
MFA For All Employees Extension — org-wide MFA OFF No MFA required PRMFA still required
Both extensions — org-wide MFA OFF No MFA required No MFA required (lowest posture — not recommended)

Long-term fix — SSO signals. If an identity provider such as Okta or Entra ID fronts Salesforce, configuring it to send accepted AMR/ACR authentication signals removes the Salesforce prompt entirely. Check the AMR and ACR columns in Login History to see what your IdP currently sends.

One caveat: Known Issue W-23493728 (July 17, 2026) — orgs holding both extensions may still see SSO users prompted to register Salesforce MFA when the IdP transmits no AMR/ACR values and org-wide MFA is enabled.

Expected Behavior, Known Issue, or Org Problem?

Diagnose by symptom:

  • Expected behavior: Desktop passkey prompts are platform-enforced Summer '26 behavior — not a fault, and not fixable per user.
  • Known issue: The mobile "Verify Identity" dead-end is a confirmed product limitation; W-23493728 additionally affects SSO orgs holding extensions.
  • Org configuration: Over-provisioned privileged permissions pull users into PRMFA scope unnecessarily — the permissions audit is the highest-impact lever.

Timeline: Key Dates

Date Event
July 1, 2026 Summer '26 MFA/PRMFA mandate takes effect; passkey prompts appear
July 2026 Mobile login changes to username-first, then passkey or password
July 13, 2026 KB 005388907 published on prompts and extensions (updated August 23)
July 17, 2026 Known Issue W-23493728 logged for SSO orgs holding both extensions
August 7–10, 2026 Troubleshooting KBs 005390721 and 005390712 published
Ongoing Extensions available on request via Salesforce Support or your account executive

Need Help With Your Salesforce MFA Rollout?

 

Passkey enforcement spans permissions, identity architecture, mobile configuration, and change management — and its failure modes are silent. Vantage Point's senior consultants help organizations audit privileged access, design MFA and SSO configurations that satisfy enforcement without breaking mobile access, and manage the rollout through managed services and compliance and security solutions. Start a conversation about your org's symptoms.

Frequently Asked Questions

Can I turn off the passkey prompt in Salesforce?

No — not through Setup alone. The org-wide MFA setting is force-enabled and greyed out, and passkey-first registration has no admin off-switch. The only sanctioned bypass is a temporary Salesforce extension; the PRMFA (Passkeys) Extension keeps MFA fully enforced while deferring passkeys for privileged users.

Why does "Verify Identity" do nothing in the Salesforce mobile app?

The app authenticates through an embedded WebView that cannot invoke FIDO2/WebAuthn passkey prompts — the tap fires a call the WebView cannot fulfill. Update to v262.010+ and use gear → "Login for Admin," or enable native browser authentication under My Domain → Authentication Configuration, then fully log out and restart the app.

Which users are required to use passkeys?

Users with the System Administrator profile (or a clone), or the Modify All Data, View All Data, Customize Application, or Author Apex permission, must use a passkey or physical security key. Everyone else can still use Salesforce Authenticator or a TOTP app via "Choose Another Verification Method."

Is the passkey prompt a bug in my org?

No. Desktop passkey prompts are expected, platform-enforced Summer '26 behavior effective July 1, 2026. The genuinely anomalous symptoms are the mobile "Verify Identity" dead-end and, for orgs holding extensions, Known Issue W-23493728.

Will Salesforce Authenticator still work after Summer '26?

Yes for non-privileged users — it satisfies standard MFA. No for privileged users — it is not phishing-resistant and does not qualify under PRMFA. Auditing privileged permissions is the fastest way to reduce how many users fall into the passkey-only group.

What extension should we ask Salesforce for?

The Phishing-Resistant MFA (Passkeys) Extension — reference KB 005388907. It keeps org-wide MFA fully enforced while temporarily holding privileged users to standard MFA and restoring "Choose Another Verification Method." Avoid the MFA For All Employees Extension unless you accept losing platform-enforced MFA altogether.

Does SSO remove the passkey requirement?

Yes, if your identity provider sends an accepted phishing-resistant AMR/ACR signal — the Salesforce prompt disappears for those logins. Check the AMR and ACR columns in Login History to confirm. Orgs holding both extensions with SSO lacking AMR/ACR signals may still see registration prompts under Known Issue W-23493728.

How Vantage Point Helps

Vantage Point is a senior-led Salesforce and HubSpot consulting partner. We help organizations audit privileged permissions, design MFA and SSO architectures that satisfy enforcement without breaking mobile access, and manage security changes through compliance and security solutions and managed services.

Sources

Salesforce is updating enforcement documentation frequently during Summer '26 — re-verify against these sources before making changes. Help links may require a Salesforce login.

David Cockrum

David Cockrum

David Cockrum is the founder and CEO of Vantage Point, a specialized Salesforce consultancy exclusively serving financial services organizations. As a former Chief Operating Officer in the financial services industry with over 13 years as a Salesforce user, David recognized the unique technology challenges facing banks, wealth management firms, insurers, and fintech companies—and created Vantage Point to bridge the gap between powerful CRM platforms and industry-specific needs. Under David’s leadership, Vantage Point has achieved over 150 clients, 400+ completed engagements, a 4.71/5 client satisfaction rating, and 95% client retention. His commitment to Ownership Mentality, Collaborative Partnership, Tenacious Execution, and Humble Confidence drives the company’s high-touch, results-oriented approach, delivering measurable improvements in operational efficiency, compliance, and client relationships. David’s previous experience includes founder and CEO of Cockrum Consulting, LLC, and consulting roles at Hitachi Consulting. He holds a B.B.A. from Southern Methodist University’s Cox School of Business.

Elements Image

Subscribe to our Blog

Get the latest articles and exclusive content delivered straight to your inbox. Join our community today—simply enter your email below!

Need help applying this to your CRM roadmap?

Talk to Vantage Point

Vantage Point helps regulated and growth-focused teams implement Salesforce, HubSpot, integrations, data migration, and managed services with practical, senior-led guidance.

Latest Articles

Salesforce Passkey MFA: Summer '26 Admin Troubleshooting Guide

Salesforce Passkey MFA: Summer '26 Admin Troubleshooting Guide

Salesforce now enforces passkey MFA for privileged users and MFA for all employees. Learn who is affected, mobile fixes, and the extension ...

Why Vantage Point Is the Top Partner for Claudeforce

Why Vantage Point Is the Top Partner for Claudeforce

Claudeforce blends Salesforce and Claude AI. Vantage Point, an official Claude partner and financial-services Salesforce specialist, leads ...

Claudeforce Trust Boundary: Why Regulated Firms Can Move Now

Claudeforce runs Claude inside the Salesforce Trust Boundary — for banks and RIAs, that changes the vendor-review math. Here's your pre-bet...