Skip to main content
All CollectionsSalesforce How-Tos and Best Practices
Enable Multi-Factor Authentication (MFA) In Salesforce
Enable Multi-Factor Authentication (MFA) In Salesforce

Enhancing your security and ensuring users login with MFA

Matthew Sanders avatar
Written by Matthew Sanders
Updated over a week ago

Enabling Multi-Factor Authentication (MFA) in Salesforce helps enhance the security of your Salesforce environment by requiring users to provide additional verification beyond their username and password. MFA is a critical component of ensuring data security, meeting industry compliance, and user accountability. Below are the steps to enable MFA, as well as utilizing a Swantide permission set.

Enable MFA

Enabling MFA is an easy process to ensure all users are required to provide an additional verification method in addition to their username and password when logging in to Salesforce orgs. Below are the steps:

  1. Navigate to Setup

  2. In the Quick Find bar, search for Identity

  3. Select Identity Verification

  4. Click the checkbox next to 'Require multi-factor authentication (MFA) for all direct UI logins to your Salesforce org'

Swantide Permission Set

For ease of use, Swantide provides customers with a pre-built permission set that requires users to use MFA when logging into Salesforce. The permission set includes settings that requires users to use MFA when signing into Salesforce. The permission set can be found by:

  1. Navigate to Setup

  2. In the Quick Find bar, search for Permission Sets

  3. Click on Permission Sets

  4. Click Multifactor Authentication

By default, no users are assigned to this permission set. To add the Standard User Group, follow the below steps:

  1. Navigate to Setup

  2. In the Quick Find bar, search for Permission Sets

  3. Click on Permission Set Groups

  4. Click on Swantide_Standard_User

  5. Click on Permission Sets in Group

  6. Click Add Permission Set

  7. Click the checkbox next to Multifactor Authentication

  8. Click Add

  9. Click Done

Initial Setup

When MFA is rolled out, all end users will be required to authenticate into Salesforce by providing another identification method outside of your password. The easiest way to accomplish this is by downloading the Salesforce Authenticator app. Once the Authenticator app is downloaded, click Add Account at the very bottom of the App Screen. This will prompt the user to copy the Two Word Phrase and enter it in the browser which invoked the MFA requirement. Once entered, the mobile app will ask to connect Salesforce to the Salesforce Authenticator App. Below is a sample screenshot of what a user will see the first time they log in after requiring MFA.

Steps to Download Salesforce Authenticator:

Did this answer your question?