Salesforce starts enforcing phishing-resistant MFA for admins in production on July 20, 2026
Salesforce began enforcing phishing-resistant multi-factor authentication for admins and other privileged users in production on July 20, 2026, kicking off a staggered rollout that blocks non‑compliant logins until enrollment is complete, as outlined in Salesforce’s enforcement notice and echoed by Cisco’s Duo Security guidance.
Phishing-resistant MFA now mandatory for Salesforce admins and privileged users
Salesforce is requiring a stronger factor for anyone with the System Administrator profile or elevated permissions like Modify All Data, View All Data, Customize Application, or Author Apex. The Admin Relations team lists these roles explicitly in its MFA update for admins. In practice, compliant methods include passkeys and hardware security keys using FIDO2/WebAuthn or built-in authenticators such as Windows Hello and Touch ID, while one-time codes and push-based apps (including Salesforce Authenticator) do not satisfy the phishing-resistant bar for these users, per Salesforce’s enforcement notice and Duo’s implementation note.
Production rollout is staggered across orgs beginning July 20, 2026
The enforcement is not a single flip; Salesforce is rolling it out in waves across instances, with production enforcement beginning July 20, 2026 and progressing over a defined window, as stated in the platform’s security update tracker and reinforced in the Trailblazer Community’s revised date announcement. That means two admins in different orgs can see the change on different days this week even though the enforcement window has started.
SSO AMR/ACR signals decide whether admins are prompted at login
The policy applies to both direct UI and SSO logins. If your identity provider doesn’t send authentication signals proving a phishing-resistant factor was used, Salesforce will prompt the user to enroll and use a compliant method at sign‑in, as explained in the admin guidance and in Salesforce’s release notes on supported SSO signals. Duo also flags this nuance for customers, noting that admins relying on SSO without the correct claims will still hit Salesforce’s phishing‑resistant requirement.
Why this enforcement matters for CRM security
Standard MFA has been widely phished through attacker-in-the-middle kits and approval fatigue. Salesforce has been signaling a shift to stronger defaults across customer orgs, framing phishing-resistant MFA for privileged users as a necessary control to protect high-impact permissions and data, as the company’s security team outlined in its broader hardening initiative. For most orgs, the immediate impact is operational: ensure every admin and privileged user has a passkey or hardware key registered and verify that your IdP is sending the right signals so critical users aren’t surprised by enrollment prompts during the rollout.




