Salesforce starts production enforcement of MFA on July 20, 2026
Salesforce is enforcing multi-factor authentication for all employee users in production starting today, July 20, 2026, with the change rolling out in staggered waves rather than a single cutover. Implementation partners have reiterated that the production wave begins now, so a working login this morning isn’t proof of exemption. See the timeline summarized by Practifi’s enforcement explainer. (practifisuccess.zendesk.com)
Salesforce MFA enforcement starts July 20 in production
Salesforce’s 2026 security program paused and then rescheduled the broad “MFA for all employees” requirement; the revised production start date remains July 20 and is delivered in waves to reduce login disruption. An engineering-focused recap of the change notes the staggered rollout and clarifies that a login may still succeed until your org’s turn in the wave, which is why administrators should verify enforcement directly in Setup rather than assume compliance. That timing is detailed in this MFA enforcement update. (softwareinsights.dev)
In practice, orgs typically feel the shift first at morning logins and whenever inactive users return. Expect a spike in help-desk tickets from users who haven’t registered a second factor yet; they’ll be prompted to enroll at next sign-in and cannot proceed without completing MFA. Practifi’s customer guidance flags this behavior and frames both the all-employee and privileged-user tracks so teams can plan support capacity. (practifisuccess.zendesk.com)
What changes for SSO customers and direct logins
If your users sign in through an identity provider (Okta, Entra ID, Ping, etc.), Salesforce looks for AMR/ACR signals confirming MFA occurred at the IdP. If those signals aren’t present, Salesforce will still challenge users to set up a verifier, even if your SSO has MFA enabled. Salesforce’s admin guide calls out the need to check whether your IdP passes the correct authentication method references, and to stop relying on the now-retired “Waive Multi-Factor Authentication for Exempt Users” shortcut. Details are outlined in the Salesforce Admins briefing on MFA enforcement. (admin.salesforce.com)
Context: phishing-resistant MFA for admins is a separate track
Today’s milestone concerns standard MFA for every employee user. Separately, Salesforce is tightening requirements for privileged users such as System Administrators and anyone with Modify All Data, View All Data, Customize Application, or Author Apex permissions; those accounts must use phishing-resistant methods like passkeys or hardware security keys, not SMS or basic TOTP apps. Cisco’s identity team summarized the privileged-user requirement in its phishing-resistant MFA for Salesforce overview. (duo.com)
Immediate implications for CRM teams
What typically happens on enforcement day is a mix of benign friction and preventable lockouts. Teams that pre-enrolled passkeys and verified AMR/ACR signaling on SSO generally sail through; teams that delayed find that admin “break glass” steps and user communications matter more than expected. A practitioner summary of the July schedule stresses verifying that the enforcement flag actually toggled in Setup and monitoring Login History for failures as the wave reaches each org. (softwareinsights.dev)





