Short answer
Phishing-resistant multi-factor authentication (MFA) uses methods such as passkeys and FIDO2 security keys that cannot be tricked into handing a code to a fake login page. Salesforce is moving users, starting with administrators, toward phishing-resistant methods as part of its 2026 security changes.
Phishing-Resistant MFA explained
Traditional MFA codes sent by text or generated in an app can be captured by a convincing phishing site. Phishing-resistant methods bind the login to the real website using public-key cryptography, so a stolen code is useless. Examples include device-based passkeys, hardware security keys and platform authenticators such as Windows Hello or Touch ID.
Firms using single sign-on can usually enforce phishing-resistant MFA at the identity provider. Admins and integration owners should plan enrollment early to avoid lockouts.
How Vantage Point helps: we prepare Salesforce orgs for MFA and login changes, including SSO configuration, admin enrollment and integration-user exceptions.
Frequently asked questions
What counts as phishing-resistant MFA?
Passkeys, FIDO2 hardware security keys and built-in platform authenticators. SMS codes and one-time passwords are not phishing-resistant.
Does SSO satisfy Salesforce's MFA requirements?
If your identity provider enforces MFA, logins through SSO can satisfy the requirement. Check that the methods your provider uses meet Salesforce's phishing-resistant criteria.
