top of page

Passkeys Now Mandatory in Salesforce Starting July 20

  • Jul 16
  • 3 min read
fingerprint scanner


Beginning this summer, Salesforce is making phishing-resistant multi-factor authentication mandatory for all administrators and users with elevated permissions. In practice, this means the method favoured by Salesforce is the passkey. If your administrators do not set up a compliant method before the deadline, they will simply be locked out at login.


Enforcement in production begins on July 20, 2026 and rolls out over fifteen days. Sandbox environments have already been subject to it since July 6. We recommend completing the setup now.


Who is affected by this change


This is where many organizations get caught. The requirement is not limited to the people you officially designate as administrators. It applies to any user with the System Administrator profile, but also to anyone holding one of the following permissions: Modify All Data, View All Data, Customize Application or Author Apex. You likely have more privileged users than you think, including old development accounts or accounts created for troubleshooting. We suggest taking inventory of your profiles and permission sets before the deadline.


Regular users, for their part, are not required to use a passkey. They will, however, need to set up standard two-factor authentication, which remains sufficient for them.


What no longer works for privileged accounts


For administrators and users with elevated permissions, traditional authentication methods are no longer accepted. Push notifications (including Salesforce Authenticator), apps that generate temporary codes such as Google Authenticator, and codes received by text message are now blocked at login. Only phishing-resistant methods are valid: passkeys, built-in device authenticators (Windows Hello, Touch ID, Face ID) and hardware security keys such as the YubiKey.


What is a passkey


A passkey is a secure login credential that replaces the traditional password. Instead of typing a password, the user authenticates using their device's biometrics (fingerprint, facial recognition) or a local passcode. The technology relies on a pair of cryptographic keys tied to the legitimate domain, which makes phishing virtually impossible: even on a fake site, the attacker gains nothing usable.


The passkey is already built into the password managers of the Chrome and Edge browsers, which makes it accessible without any additional software. Password managers such as 1Password, Bitwarden or iCloud Keychain also support it natively, provided they comply with the FIDO2/WebAuthn standard. If your organization uses a manager not explicitly listed by Salesforce, we advise confirming its FIDO2/WebAuthn compatibility before relying on it.


Please note: to use a passkey built into the device, the computer must support biometric authentication, either Windows Hello on PC or Touch ID on Mac. For Windows users, if an older workstation is not equipped with such a sensor, our recommendation is to purchase a USB fingerprint reader compatible with Windows Hello or a camera compatible with Windows Hello.


A welcome benefit comes with this change: once the passkey is set up, you can enable passwordless login. Your administrators then enter their username, use their fingerprint or facial recognition, and log in instantly. It is both more secure and faster.


How to set it up right now


Setup happens in two stages: first at the organization level, then for each user.


Step 1: allow passkeys in your organization


  1. Go to Setup, then Identity Verification.

  2. Enable the option "Let users verify their identity with a built-in authenticator."

  3. Save


Identity Verification Salesforce


To take advantage of passwordless login, also enable the corresponding passkey option on the same screen.


Step 2: add a passkey for each account


This step must be repeated by every affected user.

  1. Click your profile, then Settings.

  2. Go to the Passkey section.

  3. Register your passkey by following the on-screen instructions.


Passkeys Salesforce


In summary


This change is not optional and the deadline is fast approaching. The good news is that setup takes only a few minutes per user. The real challenge is organizational: you need to identify all affected accounts and coordinate the registration of passkeys.


Do you have questions about this transition or would you like to discuss it with our team? Contact us, we would be happy to help.


 
 

+1 (844) 878-2229

+1 (514) 418-4866

Devpresso Consulting Inc

4430 Rue Garand

Laval, QC H7L 5Z6

bottom of page