MFA is a security method that requires two or more different types of verification before you can log in to an account.
Required packages and permissions
Supported in: Lumary DC
Permission: System administrator
On their own, usernames and passwords no longer provide sufficient protection against cyberattacks. That's where MFA comes in. It's one of the simplest, most effective ways to prevent unauthorised account access and safeguard your data and your customers' data. Instead of just entering a password, MFA adds extra layers such as:
- A one-time code from an authenticator app such as Google Authenticator,
- A push notification from Microsoft Authenticator, or
- Biometric verification like a fingerprint or face scans
So, even if someone has access to your password, they still will not be able to log in they will need the additional MFA verification.
We can’t guarantee that data breaches will never occur; however, implementing multi-factor authentication (MFA) helps us take every possible measure to strengthen your data protection and overall organisational security.
To better protect customers and keep your data secure, multi-factor authentication (MFA) is a default part of the direct login process for Salesforce production orgs.
In this article we cover how to:
- enable MFA for your entire production org
- choose and enable the MFA verification method(s) available to your users
- enable third-party authenticator apps
- decide how users select a verification method during MFA registration
Enable MFA for your entire production org
Turn on multi-factor authentication (MFA) for everyone in your org with a single setting. When MFA is enabled, all internal users logging in directly with their username and password must also provide an identity verification method, such as an authenticator app or security key.
To enable or check if MFA is enabled in you production org
- Select the gear cog in the top right hand side of Lumary DC and select Setup.
- In the Quick Find box on your left type Identity Verification and select it from the results.
-
Decide on all the options you wish to use. Ensure that Require identity verification during multi-factor (MFA) is checked.
You can also check Require multi-factor authentication (MFA) for all direct UI logins to your Salesforce org and Show all verification method registration options instead of starting with built-in authentication if you are going to use them.
- Click Save.
Show/hide animation
Enable MFA for your entire production org
Head to the Salesforce article Set up Multi-Factor Authentication.
Verification methods for MFA
Multi-factor authentication (MFA) is automatically enabled for direct logins to Salesforce production orgs.
To log in, users must have at least one registered identity verification method that they provide in addition to their username and password. If they haven’t set up a verification method, they’re prompted to register one for MFA when they log in.
The registration process connects a verification method to the user’s Salesforce account. Each user must complete this step themselves. Admins can’t do it for them.
Your admin will decide and set up the verification method(s) your organisation will use.
Note: You can use different multi-factor authentication (MFA) options within one org. The options available to your users will be options that have been enabled.
For information about the security considerations of different verification methods head to the Salesforce article Configure the MFA verification methods available to users for Salesforce orgs.
Choose the MFA verification method(s) available to your users
As an admin, you must check that the different authenticator options in your production are enabled. Generally, Salesforce authenticator and third party apps are automatically available to users, however, an admin must enable the options to use built-in authenticators and physical security keys.
Salesforce supports four identity verification methods for multi-factor authentication (MFA) and device activation. These are:
- built-in authenticators
- physical security keys
- Salesforce Authenticator, and
- third-party authenticator apps
For more information about each of these methods see the Salesforce article Verification methods for Multi-Factor Authentication.
Enable the authenticator method(s) available to your uses
This allows your users to verify their identity for multi-factor authentication (MFA) or device activation with a built-in authenticator that’s already on their device, such as Touch ID or Windows Hello. When this method is enabled, users can register the built-in authenticator on their device so that it is connected to their Salesforce account.
Built-in authenticators are phishing-resistant. Enabling and requiring them is a security best practice.
- Select the gear cog in the top right hand side of Lumary DC and select Set-up and in the Quick Find box type Identity verification.
- Select Identity Verification from the search results.
- Locate the verification section and tick the identity verification methods you wish to use. These methods include:
- Let Salesforce Authenticator automatically verify identities using geolocation
- Let Salesforce Authenticator automatically verify identities based on trusted IP addresses only
- Let users verify their identity with a built-in authenticator such as Touch ID or Windows Hello
- Let users verify their identity with a physical security key (U2F or WebAuthn)
- Let users verify their identity by text (SMS).
- Click Save.
Show/hide animation
Enable MFA method(s) in your productiion orgAuthenticator Apps
You can use the Salesforce authenticator or an authenticator app of choice. Below is a list of some of more commonly used authenticator apps. We have provided links to the apps for you to view their security, functionality and terms and conditions:
- Google Authenticator – simple, works offline, very widely supported:
- Microsoft Authenticator: Google Play and Apple Store – supports push approvals + password less login
- Duo Mobile (Cisco Duo) Google Play and Apple Store – strong security, often used by companies
- Authy (by Twilio) – Google Play and Apple Store multi-device sync + encrypted backups
- LastPass Authenticator – Google Play and Apple Store integrates with LastPass ecosystem
- Salesforce
How to register an authenticator app
Important Security Disclaimer: By granting access to SSO via any of these apps you acknowledge that your security controls are shared and data is accessible by external platforms and their providers.
For more information on third party authenticator apps, head to the Salesforce article on Register a third-party authenticator app as an identity verification method for Salesforce orgs. Alternatively, you can also use the Salesforce app for MFA, head to the Salesforce article; Salesforce as an authenticator for MFA.
Decide how users select a verification method during MFA registration
You can optimise how users register verification methods for MFA and device activation based on the method you prioritise. If you are supporting multiple you can provide a list of all options available to your users to choose from. If you want to prioritise built in authenticators you can present that option first.
Follow the steps to start with the screen to connect a built in authenticator:
- Select Set-up and in the Quick Find box enter Identity.
- Select Identity Verification from the search results.
- Scroll to the Multi-Factor Authentication (MFA) section. Ensure that the Show all verification method registration options instead of starting with built-in authenticators is unticked.
- Click Save.
This means when your users log in to your production org, they will see the screen below.
Users can still register other methods for MFA by selecting Choose Another Verification Method.
For more information on how users select verification methods for MFA head to the Salesforce article, Decide how users select a verification method during MFA registration for Salesforce orgs.
You can also head to the Salesforce Help Centre for Salesforce Multi-Factor Authentication FAQs.