TL;DR: Salesforce will require phishing-resistant MFA for employee logins in sandbox environments starting June 22, 2026 and then phase enforcement into production on July 1, reflecting a wider shift away from legacy MFA for privileged access. The change reinforces that password-based and code-based methods no longer provide enough assurance when AI-driven phishing now dominates the attack path, according to Yubico.
NHIMG editorial — based on content published by Yubico: Salesforce MFA rollout and phishing-resistant authentication for privileged users
By the numbers:
- 86% of phishing attacks are now AI-driven, which raises the success rate of social engineering against legacy authentication patterns.
Questions worth separating out
Q: How should security teams implement phishing-resistant MFA for privileged SaaS access?
A: Start with the identities that can export data or change access, including IdP admins, SaaS admins, and helpdesk staff.
Q: Why do code-based MFA methods remain risky for high-risk accounts?
A: Code-based methods can be relayed, phished, or manipulated through recovery processes, which means they improve security without eliminating the attacker’s opportunity.
Q: What breaks when local privileged access is not included in MFA design?
A: Network MFA can be fully enforced while console, server, or jump-host logins remain outside the control boundary.
Practitioner guidance
- Enforce phishing-resistant MFA for privileged roles Move administrators, power users, and other elevated accounts to security keys or built-in authenticators that use FIDO2 and WebAuthn, and remove reliance on code-based factors for those roles.
- Verify authentication paths across SSO and direct login Check that the same phishing-resistant requirement applies whether users authenticate directly or through federated SSO, because policy gaps often appear between those paths.
- Register backup methods before enforcement starts Require a primary and a secondary phishing-resistant method, then test account recovery to avoid lockout when the new policy takes effect.
What's in the full article
Yubico's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step YubiKey registration flow for Salesforce user settings and advanced user details
- Specific guidance on primary and backup security key setup for administrator accounts
- Detailed authentication method distinctions between legacy MFA and phishing-resistant methods
- Practical rollout advice for enforcing the new Salesforce login requirements
👉 Read Yubico's guidance on Salesforce phishing-resistant MFA requirements →
Salesforce MFA enforcement: are your privileged users ready?
Explore further
Phishing-resistant MFA is now a privileged-access baseline, not an advanced option. Once an organisation allows administrators to rely on code-based MFA, it accepts a control that can be relayed, phished, or socially engineered. That may be acceptable for lower-risk access, but it is too weak for accounts that can reconfigure identity, security, or production systems. The practitioner conclusion is straightforward: privileged access needs a stronger assurance tier than general workforce login.
Phishing-resistant authentication will increasingly be treated as a lifecycle control, not just an authentication control. Once privileged users are moved to device-bound methods, the real work shifts to enrollment, backup registration, recovery, and reassignment when roles change. Teams that only update login policy without reworking the surrounding lifecycle will keep weak paths alive.
A question worth separating out:
Q: Who should be first in line for phishing-resistant authentication?
A: Privileged users, remote access populations, and any identity that reaches sensitive business systems should go first. These accounts offer the highest payoff for attackers and the fastest containment benefit for defenders. Once those paths are protected, teams can tackle broader workforce rollout with less operational pressure.
👉 Read our full editorial: Salesforce’s MFA rollout shows phishing-resistant auth is now baseline