
The New Salesforce MFA Requirements
In February of 2022, Salesforce started mandating that all customers enable multi-factor authentication (MFA) for their users regardless of how they access their accounts. Beginning April 8, 2024, Salesforce automatically enabled MFA for all direct logins – but not with organizations that are using Single Sign-On (SSO). Also, starting with the Summer ‘24 release, Salesforce will periodically notify all System Administrators in the organization until the instance is fully compliant with the MFA requirements (See MFA Advisory Timeline for more announcement details).
If a Salesforce org uses an Authentication Scheme such as Single Sign-On (SSO) and has disabled direct login access to facilitate user access to Salesforce, by default Salesforce will not require the organization to activate SSO Multi-Factor Authentication (MFA). However, according to Salesforce’s Terms of Service, the SSO solution must incorporate MFA. It is important to note that Salesforce will not automatically activate MFA within the organization’s SSO setup. Instead, System Administrators or Users who have Administrator capability are responsible for ensuring this feature is enabled or activated. Some SSO providers have their own MFA application (e.g. Microsoft or AWS), but the organization can also use Salesforce Authenticator (native MFA of Salesforce) to meet this security requirement.
In scenarios where a Salesforce organization enables Direct UI Login with credentials (Username and Password) alongside SSO, it is important to implement an additional layer of authentication. If the Organization is not enforcing MFA for direct login access to Salesforce, despite having MFA activated for Single Sign On, this leaves a gap for unauthorized access or entry, and does not comply with the Salesforce MFA security policy. It is important that all login methods, whether through Direct Login or SSO, are secured with MFA to ensure enhanced security.
