🔥 600+ people already subscribed. Why not you? Get our newsletter with handy code snippets, tips, and marketing automation insights.

background shape
background shape

Salesforce starts enforcing phishing-resistant MFA for admins in production on July 20, 2026

Salesforce began enforcing phishing-resistant multi-factor authentication for admins and other privileged users in production on July 20, 2026, kicking off a staggered rollout that blocks non‑compliant logins until enrollment is complete, as outlined in Salesforce’s enforcement notice and echoed by Cisco’s Duo Security guidance.

Phishing-resistant MFA now mandatory for Salesforce admins and privileged users

Salesforce is requiring a stronger factor for anyone with the System Administrator profile or elevated permissions like Modify All Data, View All Data, Customize Application, or Author Apex. The Admin Relations team lists these roles explicitly in its MFA update for admins. In practice, compliant methods include passkeys and hardware security keys using FIDO2/WebAuthn or built-in authenticators such as Windows Hello and Touch ID, while one-time codes and push-based apps (including Salesforce Authenticator) do not satisfy the phishing-resistant bar for these users, per Salesforce’s enforcement notice and Duo’s implementation note.

Production rollout is staggered across orgs beginning July 20, 2026

The enforcement is not a single flip; Salesforce is rolling it out in waves across instances, with production enforcement beginning July 20, 2026 and progressing over a defined window, as stated in the platform’s security update tracker and reinforced in the Trailblazer Community’s revised date announcement. That means two admins in different orgs can see the change on different days this week even though the enforcement window has started.

SSO AMR/ACR signals decide whether admins are prompted at login

The policy applies to both direct UI and SSO logins. If your identity provider doesn’t send authentication signals proving a phishing-resistant factor was used, Salesforce will prompt the user to enroll and use a compliant method at sign‑in, as explained in the admin guidance and in Salesforce’s release notes on supported SSO signals. Duo also flags this nuance for customers, noting that admins relying on SSO without the correct claims will still hit Salesforce’s phishing‑resistant requirement.

Why this enforcement matters for CRM security

Standard MFA has been widely phished through attacker-in-the-middle kits and approval fatigue. Salesforce has been signaling a shift to stronger defaults across customer orgs, framing phishing-resistant MFA for privileged users as a necessary control to protect high-impact permissions and data, as the company’s security team outlined in its broader hardening initiative. For most orgs, the immediate impact is operational: ensure every admin and privileged user has a passkey or hardware key registered and verify that your IdP is sending the right signals so critical users aren’t surprised by enrollment prompts during the rollout.

Oh hi there 👋
I have a SSJS skill for you.

Sign up now to get an SSJS skill that can be used with your AI companion

We don’t spam! Read our privacy policy for more info.

Share With Others

The Author
Marcel Szimonisz Platinum

Marcel Szimonisz

MarTech consultant

I specialize in solving problems, automating processes, and driving innovation through major marketing automation platforms, particularly Salesforce Marketing Cloud and Adobe Campaign.

Your email address will not be published. Required fields are marked *

Buy me a coffee
Subscribe

Get exclusive tips, scripts and news

Choose your topics

We don’t spam! Read our privacy policy for more info.

Similar posts