Logo Logo Logo Logo Logo
  • Services
    • Salesforce Services
      • Financial Services
        • Investment Banking
        • Private Equity
        • Venture Capital
      • Healthcare
      • Manufacturing
    • HubSpot Services
      • Financial Services
      • Healthcare
      • Manufacturing
    • Claude Services
  • Resources
    • The Scalable Business Framework Book
    • The Fast Slow Motion Podcast
    • AI in Action
    • Blog
  • About Us
    • Meet the Team
    • Reviews
    • Success Stories
  • Careers
    • Why Work at Fast Slow Motion?
    • Roles at Fast Slow Motion
  • Get In Touch
  • Services
    • Salesforce Services
      • Financial Services
        • Investment Banking
        • Private Equity
        • Venture Capital
      • Healthcare
      • Manufacturing
    • HubSpot Services
      • Financial Services
      • Healthcare
      • Manufacturing
    • Claude Services
  • Resources
    • The Scalable Business Framework Book
    • The Fast Slow Motion Podcast
    • AI in Action
    • Blog
  • About Us
    • Meet the Team
    • Reviews
    • Success Stories
  • Careers
    • Why Work at Fast Slow Motion?
    • Roles at Fast Slow Motion
  • Get In Touch
office-work-with-charts

What Phishing-Resistant MFA Means for Your Salesforce Admins

Posted June 26, 2026 in FSM Podcast Resources, Salesforce, Salesforce News, Salesforce Update by Anna Farley

Most conversations about Salesforce security stop at multi-factor authentication. Turn it on, make sure everyone’s using it, move on. The Summer ’26 release introduces a requirement that goes further — and it applies specifically to the users in your Salesforce environment who have the most access.

If your org has system administrators, or users with broad permissions to configure or modify the platform, they’re now subject to a stricter form of authentication called phishing-resistant MFA. Understanding what it is, who it affects, and what it requires is worth your time before the enforcement deadlines hit.

What Makes Standard MFA Vulnerable

Standard MFA — the kind where you enter a code from an authenticator app or receive a text message — is significantly more secure than a password alone. But it has a known weakness. A one-time code can be intercepted. A sophisticated attacker can create a fake login page that captures both a user’s password and their MFA code in real time, then uses them immediately to gain access before the code expires.

This type of attack is called phishing, and it’s effective precisely because it works even when a user thinks they’re doing everything right. They entered their password. They entered their code. They had no way of knowing the site they were on wasn’t the real one.

Phishing-resistant MFA eliminates this attack vector entirely by using authentication methods that can’t be intercepted or replicated, regardless of where the login attempt originates.

Who Is Considered a Privileged User

Salesforce defines privileged users as anyone with one or more of the following permissions: system administrator profile, modify all data, view all data, customize application, or author Apex. These are the users who can make broad changes to your Salesforce environment — creating objects, modifying fields, writing code, accessing all records regardless of sharing rules.

In many businesses, this list is longer than it should be. Permissions get granted over time for specific reasons, and they rarely get revisited. Before the enforcement deadlines arrive, it’s worth pulling a list of every user who falls into one of these categories and asking whether each person genuinely needs that level of access.

Users who do need it will have to complete phishing-resistant authentication every time they log in. Users who don’t need it are carrying an unnecessary security risk and can have those permissions reduced.

What Phishing-Resistant MFA Actually Requires

There are two options that qualify as phishing-resistant under Salesforce’s standard.

Hardware Security Keys

A hardware security key is a small physical device — commonly a USB stick or an NFC-enabled card — that a user plugs in or taps when prompted during login. The key uses cryptography to verify the login is happening on a legitimate site, which means it simply doesn’t work on a fake page. An attacker can’t intercept or replicate the response.

YubiKey is the most widely known brand, but there are several options available. For businesses with a small number of privileged users, hardware keys are a straightforward solution. The main considerations are cost, distribution, and what happens when a key is lost.

Built-In Biometrics

The more practical option for most businesses is built-in biometrics — Touch ID on a MacBook, Face ID on newer Apple devices, or Windows Hello on a PC. These use the same underlying cryptographic standard as hardware keys and are fully phishing-resistant. The difference is that the authentication hardware is already built into the device the user is working on.

For most businesses with privileged users who work on company-issued laptops, this is the path of least resistance. It requires no additional hardware purchases, the setup process is managed through the operating system the user already knows, and the authentication experience is fast — a fingerprint or a glance.

The catch is that biometric authentication is tied to a specific device. A user who needs to access Salesforce from a different computer will need a hardware key or another approved method as a backup.

The Shared Login Problem

One of the more complicated scenarios this requirement creates is shared logins. Some businesses use a single set of credentials for multiple people to access Salesforce — a shared admin account that several team members sign into when they need to make configuration changes.

Phishing-resistant MFA is difficult to implement with shared logins because biometric authentication is personal to the individual, and hardware keys tied to a shared account create their own security and logistics problems.

If your business uses shared admin credentials, this needs to be addressed before enforcement hits. The most robust solution is moving to individual accounts with single sign-on, which allows each person to authenticate using their own credentials and biometric method while still accessing the shared environment. This requires planning and setup time, so it’s not something to leave until the last minute.

What to Do Before the Deadline

Start with a clear picture of who your privileged users are. Your Salesforce administrator can pull this list. Once you have it, two conversations need to happen: one about which users genuinely need those permissions, and one about how each remaining privileged user is going to meet the phishing-resistant requirement.

For most businesses the biometric path is the right answer. Confirm that privileged users are on company-issued hardware with biometric authentication enabled, walk them through the Salesforce setup process, and test it before the production enforcement date.

If your environment involves shared logins, contract workers accessing the system remotely, or users on non-standard hardware, bring your Salesforce administrator or consulting partner into the conversation early. These scenarios have solutions, but they take more time to implement correctly.

If you’re not sure where your environment stands or what any of this means for your specific setup, reach out using the link in the show notes.

Listen to the full podcast episode here.

Related Resources

  • Salesforce Is Enforcing MFA — And Your Business May Not Be Ready
  • Who Should Have Admin Access in Your Salesforce Org — And Why It Matters More Than Ever
  • Why Your Team Might Get Stopped Mid-Report in Salesforce — And What to Tell Them
  • The Salesforce Summer ’26 Release: What Business Leaders Actually Need to Know

Tags:
Business Leaders, Salesforce, Salesforce Admin, Salesforce Login Security Changes 2026, Salesforce MFA, Salesforce Security


Categories
  • AI
  • Business
  • Claude
  • Company News
  • Data
  • Entrepreneurship
  • Growth
  • HubSpot
  • Human Resources
  • Leadership
  • Marketing
  • Process Improvement
  • Sales
  • Salesforce
  • Salesforce Adoption
  • Salesforce News
  • Salesforce Update
  • Social Media
  • Software
  • Technology
  • The Scalable Business Framework
Search

Contact Us

Fast Slow Motion
120 19th Street North, Suite 2001
Birmingham, AL 35203

(866) 917-8833 main
(866) 917-8833 fax

info@fastslowmotion.com

FSM Offices Across the U.S.

FSM OFFICES ACROSS THE U.S.
FSM CLIENTS IN 50 STATES, CANADA, EUROPE & THE CARIBBEAN

Fast Slow Motion is a Salesforce Summit Tier and HubSpot Elite Tier Partner

SALESFORCE CONSULTING LOCATIONS | HUBSPOT CONSULTING LOCATIONS

Terms of Use | Privacy Policy | © 2014-2026 Fast Slow Motion