Salesforce Dictionary - Free Salesforce GlossarySalesforce Dictionary
DictionaryIIdentity Verification
AdministrationAdvanced

Identity Verification

Identity Verification is a Setup page where administrators configure the methods and policies used to verify user identities during login and high-assurance actions.

§ 01

Definition

Identity Verification is a Setup page where administrators configure the methods and policies used to verify user identities during login and high-assurance actions. Options include Salesforce Authenticator, TOTP apps, SMS verification, email verification, and physical security keys.

§ 02

In plain English

👋 Study buddy

Here's a simple way to think about it: Identity Verification is the umbrella for every "prove it's really you" flow - Salesforce Authenticator, TOTP apps, SMS, email, security keys. The methods are the building blocks; policy decides when each is invoked.

§ 03

Worked example

scenario · real-world use

The admin at Granite Financial configures Identity Verification to require Salesforce Authenticator for all users when they log in from an unrecognized device or IP address. She also enables security key support for the executive team, who use YubiKey devices as an additional verification factor for accessing sensitive financial data.

§ 04

Why Identity Verification is the umbrella for every "prove it's really you" flow

Salesforce verifies user identity in many places - at login from a new IP, before a high-trust action like resetting an admin password, when MFA is required by policy. Identity Verification is the Setup page that consolidates the methods: Salesforce Authenticator, TOTP apps like Google Authenticator and 1Password, SMS, email, physical security keys. Each is a different trade-off between user friction and assurance level, and this page is where you decide which methods your users can rely on.

The reason the choice matters is that the worst-on-availability method (e.g. SMS to a phone the user no longer has) becomes the recovery method some user will desperately need on a Tuesday morning. Enable a method that works when SMS doesn't (an authenticator app or security key); discourage SMS-only as the registered method even if you allow it; and document the recovery process so admins can help users who get locked out by their own MFA.

§ 05

How to set up Identity Verification

Identity Verification (the modern name for MFA configuration) controls when and how users prove they are who they say they are — TOTP authenticator apps, security keys, SMS, email codes. Since 2022, MFA is contractually required for Salesforce admin and high-privilege users.

  1. Open Setup → Identity Verification

    Setup gear → Quick Find: Identity Verification → Identity Verification.

  2. Review verification methods enabled

    Salesforce Authenticator (push-notification app) / TOTP (Authy, Google Authenticator) / U2F Security Keys / SMS / Email. Pick which to enable.

  3. Set when to challenge

    Always (every login) / when login risk is detected (default) / never (not allowed for admin profiles).

  4. Open Setup → Multi-Factor Authentication Assistant

    Salesforce-provided wizard to roll out MFA per profile. Check progress and identify users not yet enrolled.

  5. Tick Require MFA for Logins for relevant profiles

    Setup → Profile → System & User Permissions → tick Multi-Factor Authentication for User Interface Logins. Users on these profiles must enroll a verification method.

  6. Communicate to users

    First login after this change prompts users to enroll. Provide enrollment instructions and a help-channel for confused users.

Key options
Salesforce Authenticatorremember

Push notifications. The most user-friendly method.

TOTPremember

Standards-based time-based one-time passwords. Works with any TOTP app.

U2F / Security Keysremember

Hardware tokens (YubiKey, etc.). Strongest, most user-resistant.

SMSremember

Being deprecated as a method due to SIM-swap risk. Salesforce recommends alternatives.

Emailremember

Fallback method. Less secure than TOTP / hardware.

Gotchas
  • MFA is contractually required for Salesforce admins and high-privilege users since February 2022. Non-compliance can affect your contract. Don't disable MFA on admin profiles.
  • SMS as a verification method is being deprecated. SIM-swap attacks are a real threat — Salesforce recommends moving users to TOTP or hardware keys.
  • First-time enrollment can confuse users. Pair the rollout with clear comms — "On your next login you'll be asked to set up MFA, here's how."
§ 06

How organizations use Identity Verification

Vanguard Solutions

Standardized on Salesforce Authenticator + security keys; phased out SMS for high-assurance workflows after a SIM-swap incident.

Pacific Crest Bank

Compliance team enforced Authenticator-only for admin workflows; TOTP-eligible methods cover the rest of the user base.

BlueRiver Health

Patient-facing clinicians use Salesforce Authenticator with biometric second factors; enrollment is part of standard onboarding.

Was this entry helpful?
Help us write better definitions. Quick reactions or detailed edit suggestions.
§

Test your knowledge

Q1. Can a Salesforce admin configure Identity Verification without writing code?

Q2. Why is understanding Identity Verification important for Salesforce admins?

Q3. In which area of Salesforce would you typically find Identity Verification?

§

Discussion

Loading…

Loading discussion…