Salesforce Dictionary - Free Salesforce GlossarySalesforce Dictionary
Full Identity Verification entry
How-to guide

How to set up Identity Verification in Salesforce

Identity Verification (the modern name for MFA configuration) controls when and how users prove they are who they say they are — TOTP authenticator apps, security keys, SMS, email codes. Since 2022, MFA is contractually required for Salesforce admin and high-privilege users.

By Dipojjal Chakrabarti · Editor, Salesforce DictionaryLast updated Apr 20, 2026

Identity Verification (the modern name for MFA configuration) controls when and how users prove they are who they say they are — TOTP authenticator apps, security keys, SMS, email codes. Since 2022, MFA is contractually required for Salesforce admin and high-privilege users.

  1. Open Setup → Identity Verification

    Setup gear → Quick Find: Identity Verification → Identity Verification.

  2. Review verification methods enabled

    Salesforce Authenticator (push-notification app) / TOTP (Authy, Google Authenticator) / U2F Security Keys / SMS / Email. Pick which to enable.

  3. Set when to challenge

    Always (every login) / when login risk is detected (default) / never (not allowed for admin profiles).

  4. Open Setup → Multi-Factor Authentication Assistant

    Salesforce-provided wizard to roll out MFA per profile. Check progress and identify users not yet enrolled.

  5. Tick Require MFA for Logins for relevant profiles

    Setup → Profile → System & User Permissions → tick Multi-Factor Authentication for User Interface Logins. Users on these profiles must enroll a verification method.

  6. Communicate to users

    First login after this change prompts users to enroll. Provide enrollment instructions and a help-channel for confused users.

Key options
Salesforce Authenticatorremember

Push notifications. The most user-friendly method.

TOTPremember

Standards-based time-based one-time passwords. Works with any TOTP app.

U2F / Security Keysremember

Hardware tokens (YubiKey, etc.). Strongest, most user-resistant.

SMSremember

Being deprecated as a method due to SIM-swap risk. Salesforce recommends alternatives.

Emailremember

Fallback method. Less secure than TOTP / hardware.

Gotchas
  • MFA is contractually required for Salesforce admins and high-privilege users since February 2022. Non-compliance can affect your contract. Don't disable MFA on admin profiles.
  • SMS as a verification method is being deprecated. SIM-swap attacks are a real threat — Salesforce recommends moving users to TOTP or hardware keys.
  • First-time enrollment can confuse users. Pair the rollout with clear comms — "On your next login you'll be asked to set up MFA, here's how."

See the full Identity Verification entry

Identity Verification includes the definition, worked example, deep dive, related terms, and a quiz.