Salesforce is rolling out a two-tier MFA enforcement strategy in 2026. Starting June 22 in sandboxes and July 1 in production, admins and privileged users must use phishing-resistant authentication methods. Then, on July 20, the requirement expands to every employee user in your org. Here's what's changing, who's affected, and how to prepare your entire organization.
Salesforce's 2026 security overhaul isn't a single MFA requirement—it's two overlapping mandates:
Tier 1 (July 1, 2026): Phishing-resistant MFA for admins and privileged users only.
Tier 2 (July 20, 2026): Standard MFA for every employee user.
Understanding the difference between these tiers is critical. They have different deadlines, different acceptable methods, and different implementation paths.
A user needs only one of these to be in scope:
Admin-level credentials are the highest-value phishing target. A single compromised admin session can expose or alter an entire org. By requiring a phishing-resistant method for these accounts, Salesforce is raising the bar for attackers trying to gain administrative access.
Standard push notifications and SMS codes are vulnerable to MFA fatigue attacks. An attacker can bombard a user with push notifications until they accidentally approve one. SMS codes can be intercepted or relayed through adversary-in-the-middle attacks. Phishing-resistant methods like security keys and passkeys are immune to these attacks because they cryptographically verify the login domain—a fake login page can't trick them.
Direct UI Login: The privileged user registers a passkey or security key directly in Salesforce. When they try to log in without one, Salesforce blocks them.
SSO Login (Okta, Azure AD, Ping, etc.): Salesforce can't enforce a phishing-resistant method inside a third-party SSO flow. Your identity and security team must configure the SSO provider itself to require a phishing-resistant factor for these users. This is the step organizations most often miss.
If your org uses SSO, coordinate with your identity team now. They need to set up conditional access policies or MFA rules in your SSO provider to require phishing-resistant authentication for users with Salesforce admin roles.
|
Environment |
Enforcement Starts |
Stagger Window |
|
Sandboxes |
June 22, 2026 |
~7 days |
|
Production |
July 1, 2026 |
~30 days |
Salesforce has required MFA since February 2022, but enforcement has largely relied on self-attestation. Many orgs still have users without it fully set up. Starting June 22, 2026 in sandboxes and July 20, 2026 in production, Salesforce is closing that gap with direct, technical enforcement at login for every employee user.
Every employee or internal user who logs into Salesforce directly or via SSO. This includes:
For direct username/password login: The Salesforce Authenticator mobile app (push notification) is the standard method most orgs will use. Security keys and built-in device authenticators are also accepted but optional at this tier.
For SSO login: The SSO provider itself must be configured to require MFA. Salesforce enforcement checks that the SSO session included an MFA step—it doesn't layer its own on top.
|
Environment |
Enforcement Starts |
Stagger Window |
|
Sandboxes |
June 22, 2026 |
~7 days |
|
Production |
July 20, 2026 |
~30 days |
If a privileged user hasn't set up phishing-resistant MFA by July 1, their login will be blocked. They'll see an error message directing them to set up a compliant method. Only after they register a security key or passkey will they be able to log in again.
This creates operational risk if you have multiple admins and one of them is unavailable during the enforcement window.
Users without a registered MFA method are blocked from logging in once enforcement reaches their org—no self-service bypass. Because this hits every employee user, unprepared orgs typically see a help-desk spike, not just a handful of tickets.
SSO orgs that assumed "SSO means we're covered" may discover their identity provider was never actually configured to require an MFA step.
This two-tier approach is part of Salesforce's broader shift toward zero-trust security. The platform is moving away from the assumption that a single strong password plus any MFA is sufficient. Instead, it's implementing layered controls: phishing-resistant MFA for high-value accounts, step-up authentication for sensitive actions, and anomaly detection for suspicious logins.
For organizations managing complex Salesforce environments, staying ahead of these changes requires planning and communication. Consider working with experienced Salesforce consulting partners who can help you identify privileged users, configure SSO correctly, and roll out MFA smoothly across both tiers.
Understanding how this fits into your broader sales activity tracking and territory management strategies will also help you appreciate the security context. Contact us today if you want to discuss how to prepare your org for these changes.