Skip to content

Glossary · Compliance & Regulation

Phishing-Resistant MFA

Also known as: Passkeys, FIDO2

Short answer

Phishing-resistant multi-factor authentication (MFA) uses methods such as passkeys and FIDO2 security keys that cannot be tricked into handing a code to a fake login page. Salesforce is moving users, starting with administrators, toward phishing-resistant methods as part of its 2026 security changes.

Phishing-Resistant MFA explained

Traditional MFA codes sent by text or generated in an app can be captured by a convincing phishing site. Phishing-resistant methods bind the login to the real website using public-key cryptography, so a stolen code is useless. Examples include device-based passkeys, hardware security keys and platform authenticators such as Windows Hello or Touch ID.

Firms using single sign-on can usually enforce phishing-resistant MFA at the identity provider. Admins and integration owners should plan enrollment early to avoid lockouts.

How Vantage Point helps: we prepare Salesforce orgs for MFA and login changes, including SSO configuration, admin enrollment and integration-user exceptions.

Frequently asked questions

What counts as phishing-resistant MFA?

Passkeys, FIDO2 hardware security keys and built-in platform authenticators. SMS codes and one-time passwords are not phishing-resistant.

Does SSO satisfy Salesforce's MFA requirements?

If your identity provider enforces MFA, logins through SSO can satisfy the requirement. Check that the methods your provider uses meet Salesforce's phishing-resistant criteria.

Last reviewed October 2, 2026 by the Vantage Point team. Browse all glossary terms →