The requirement to use multi-factor authentication (MFA) when accessing Salesforce products went into effect on February 1, 2022. All users must now use MFA when they log in to Salesforce, whether they’re logging in directly or using single sign-on (SSO). To help customers satisfy this requirement, in the first half of 2023, Salesforce is automatically enabling MFA for direct logins. In the September 2023 timeframe, we’re enforcing MFA by making it a permanent part of the Salesforce login process. To avoid disruptions to your users when these milestones occur, enable MFA as soon as possible.
Where: This change applies to Lightning Experience, Salesforce Classic, and all Salesforce mobile apps in all editions.
When: As of February 1, 2022, Salesforce customers are contractually required to use MFA when accessing Salesforce products, according to the Salesforce Trust and Compliance Documentation. For a subset of customers, a release update that automatically enables MFA for all direct Salesforce logins is available in Winter ’23 and takes effect when the Spring ’23 release rolls out. For all other customers, this release update applies in a later release. For more information, see MFA To Be Auto-Enabled for Some Customers in Spring ’23 (Release Update). To monitor the MFA enforcement milestone schedule, see the MFA Enforcement Roadmap.
How: To see if you’re affected by the MFA Auto-Enablement Release Update, monitor the Release Update node in Setup.
To implement and roll out MFA on your own:
- Check out the Multi-Factor Authentication Assistant. In Lightning Experience, from Setup, in the Quick Find box, enter MFA, and then select Multi-Factor Authentication Assistant.
- Get customizable templates for rollout planning and change management by downloading the MFA Rollout Pack.
- Make sure that your implementation satisfies the terms of the MFA requirement with the MFA Requirement Checker.
Be Ready for Multi-Factor Authentication Auto-Enablement (salesforce.com)