If users in your org suddenly started seeing passkey prompts after July 1, 2026, you are not looking at a misconfiguration — you are looking at a platform-enforced change. With the Summer '26 release (v262), Salesforce began enforcing MFA for all employee users and phishing-resistant MFA for privileged users, with passkeys as the default first option in MFA registration.
This guide covers what changed, who is forced into passkeys, why mobile "Verify Identity" does nothing, and the admin actions — including a Salesforce-supported extension request — that reduce friction without weakening security. It is the operational companion to our Salesforce security overhaul preparation guide.
What changed? Effective July 1, 2026, Salesforce enforces MFA for all employee users and phishing-resistant MFA (passkeys or security keys) for privileged users, with passkey-first registration for direct logins.
Who is affected? Every org with direct UI logins. Users with the System Administrator profile (or a clone), Modify All Data, View All Data, Customize Application, or Author Apex must use a passkey; Authenticator and TOTP apps no longer qualify for them.
Is it a bug? Mostly no. Desktop passkey prompts are expected platform behavior; the mobile app's dead "Verify Identity" button is a confirmed product limitation with workarounds.
What should admins do? Audit privileged permissions, fix mobile (app v262.010+, native browser authentication), and — if needed — ask Salesforce for the temporary PRMFA (Passkeys) Extension, which keeps MFA fully enforced while deferring passkeys.
With Summer '26, Salesforce flipped three enforcement switches at the platform level, effective July 1, 2026 — which is why the prompts appeared almost overnight:
Salesforce also changed three Setup → Identity Verification settings with no admin action:
None of this is caused by anything in your org, and there is no Setup off-switch — Salesforce presents passkeys first deliberately because they are its most phishing-resistant method.
Whether a user can pick a different MFA method depends entirely on their permissions, not their role or license.
Privileged users — passkey required, no alternative. Anyone with the System Administrator profile (or a clone), or the Modify All Data, View All Data, Customize Application, or Author Apex permission, is held to phishing-resistant MFA. "Choose Another Verification Method" is removed for these users; only a passkey — or SSO transmitting an accepted phishing-resistant AMR/ACR signal — satisfies the requirement.
Non-privileged users — passkey-first, but choice remains. Everyone else can click "Choose Another Verification Method" and register Salesforce Authenticator or a TOTP app, which satisfies standard MFA. Passkeys stay first by design, and even compliant users keep seeing the nudge — expected behavior, not an error.
Note: "Waive Multi-Factor Authentication for Exempt Users" no longer exempts anyone post-enforcement without a Salesforce-approved extension.
This is a confirmed known product limitation. The standard mobile app authenticates through an embedded WebView that cannot invoke the FIDO2/WebAuthn passkey authenticator. When a privileged user taps "Verify Identity," the button fires a WebAuthn call the WebView cannot fulfill — no navigation, no prompt, no error. It primarily blocks privileged users.
Supported fixes:
Edge cases:
Work these five actions in order; the first has the highest impact.
Counterintuitively, the fastest path to fewer clicks is leaning into passkeys rather than around them — once registered, a passkey is a single-step, phishing-resistant login:
Salesforce grants temporary extensions on request; ask Salesforce Support or your account executive:
How each configuration plays out for direct UI logins:
| Configuration | Non-Privileged Users | Privileged Users (incl. Admins) |
|---|---|---|
| Default — no extensions (org-wide MFA locked ON) | Standard MFA required (passkey-first registration; other methods selectable) | PRMFA required — passkey only, no alternative |
| PRMFA (Passkeys) Extension only — org-wide MFA ON | Standard MFA required | Standard MFA required — "Choose Another Verification Method" restored |
| MFA For All Employees Extension — org-wide MFA OFF | No MFA required | PRMFA still required |
| Both extensions — org-wide MFA OFF | No MFA required | No MFA required (lowest posture — not recommended) |
Long-term fix — SSO signals. If an identity provider such as Okta or Entra ID fronts Salesforce, configuring it to send accepted AMR/ACR authentication signals removes the Salesforce prompt entirely. Check the AMR and ACR columns in Login History to see what your IdP currently sends.
One caveat: Known Issue W-23493728 (July 17, 2026) — orgs holding both extensions may still see SSO users prompted to register Salesforce MFA when the IdP transmits no AMR/ACR values and org-wide MFA is enabled.
Diagnose by symptom:
| Date | Event |
|---|---|
| July 1, 2026 | Summer '26 MFA/PRMFA mandate takes effect; passkey prompts appear |
| July 2026 | Mobile login changes to username-first, then passkey or password |
| July 13, 2026 | KB 005388907 published on prompts and extensions (updated August 23) |
| July 17, 2026 | Known Issue W-23493728 logged for SSO orgs holding both extensions |
| August 7–10, 2026 | Troubleshooting KBs 005390721 and 005390712 published |
| Ongoing | Extensions available on request via Salesforce Support or your account executive |
Passkey enforcement spans permissions, identity architecture, mobile configuration, and change management — and its failure modes are silent. Vantage Point's senior consultants help organizations audit privileged access, design MFA and SSO configurations that satisfy enforcement without breaking mobile access, and manage the rollout through managed services and compliance and security solutions. Start a conversation about your org's symptoms.
No — not through Setup alone. The org-wide MFA setting is force-enabled and greyed out, and passkey-first registration has no admin off-switch. The only sanctioned bypass is a temporary Salesforce extension; the PRMFA (Passkeys) Extension keeps MFA fully enforced while deferring passkeys for privileged users.
The app authenticates through an embedded WebView that cannot invoke FIDO2/WebAuthn passkey prompts — the tap fires a call the WebView cannot fulfill. Update to v262.010+ and use gear → "Login for Admin," or enable native browser authentication under My Domain → Authentication Configuration, then fully log out and restart the app.
Users with the System Administrator profile (or a clone), or the Modify All Data, View All Data, Customize Application, or Author Apex permission, must use a passkey or physical security key. Everyone else can still use Salesforce Authenticator or a TOTP app via "Choose Another Verification Method."
No. Desktop passkey prompts are expected, platform-enforced Summer '26 behavior effective July 1, 2026. The genuinely anomalous symptoms are the mobile "Verify Identity" dead-end and, for orgs holding extensions, Known Issue W-23493728.
Yes for non-privileged users — it satisfies standard MFA. No for privileged users — it is not phishing-resistant and does not qualify under PRMFA. Auditing privileged permissions is the fastest way to reduce how many users fall into the passkey-only group.
The Phishing-Resistant MFA (Passkeys) Extension — reference KB 005388907. It keeps org-wide MFA fully enforced while temporarily holding privileged users to standard MFA and restoring "Choose Another Verification Method." Avoid the MFA For All Employees Extension unless you accept losing platform-enforced MFA altogether.
Yes, if your identity provider sends an accepted phishing-resistant AMR/ACR signal — the Salesforce prompt disappears for those logins. Check the AMR and ACR columns in Login History to confirm. Orgs holding both extensions with SSO lacking AMR/ACR signals may still see registration prompts under Known Issue W-23493728.
Vantage Point is a senior-led Salesforce and HubSpot consulting partner. We help organizations audit privileged permissions, design MFA and SSO architectures that satisfy enforcement without breaking mobile access, and manage security changes through compliance and security solutions and managed services.
Salesforce is updating enforcement documentation frequently during Summer '26 — re-verify against these sources before making changes. Help links may require a Salesforce login.