Salesforce is going to require passkeys for administrators and for users who hold certain elevated permissions. Production rollout starts July 1, 2026. The aim is to shut down "push bombing" attacks by requiring physical presence at the device during login.
Background
Traditional multi-factor authentication can be worn down by an attacker firing login request after login request at a user's device until someone taps approve. Passkeys use device biometrics such as Touch ID or Windows Hello, or a hardware security key like a YubiKey, so there is stronger assurance that the user is actually at the machine.
Key dates
- Sandbox rollout begins June 22, 2026, and runs for seven days.
- Production rollout begins July 1, 2026, and runs for 30 days.
Who is affected?
Passkeys become mandatory for:
- Users with administrator-level access.
- Users with permissions such as
Modify All Data,View All Data,Customize Application, orAuthor Apex.
Go through your Profiles and Permission Sets properly before you assume you know the list. Older orgs in particular tend to have handed out broad data visibility to people nobody thinks of as admins.
Identifying affected users with SOQL
This SOQL query pulls the users with the relevant permissions:
SELECT
Assignee.Id,
Assignee.Name,
Assignee.Email,
Assignee.Username,
Assignee.IsActive,
PermissionSet.Name,
PermissionSet.Profile.Name,
PermissionSet.PermissionsModifyAllData,
PermissionSet.PermissionsViewAllData,
PermissionSet.PermissionsCustomizeApplication,
PermissionSet.PermissionsAuthorApex
FROM
PermissionSetAssignment
WHERE
Assignee.IsActive = TRUE
AND (
PermissionSet.PermissionsModifyAllData = TRUE
OR PermissionSet.PermissionsViewAllData = TRUE
OR PermissionSet.PermissionsCustomizeApplication = TRUE
OR PermissionSet.PermissionsAuthorApex = TRUE
)
It returns every active user assigned to a permission set carrying those elevated permissions, whether the permission came from a Profile or a Permission Set.
Passkey options
Users get a choice here.
Device-bound passkeys tie to a PC, Mac, or mobile app and use biometrics. They are free. The catch is that they need cloud backup, or the user is locked out when the primary device is not around. Be careful about leaning on a password manager if it does not meet Salesforce's current security criteria.
Security keys are physical USB tokens. They are device agnostic, which suits anyone who switches machines or does not always carry a laptop. They are one more thing to lose, and they carry a recurring cost of roughly $35 USD per user.
Registering both is worth recommending to users with several devices, or anyone who wants a backup option.
Implementation steps
Administrator setup
- Go to Setup > Identity > Identity Verification.
- Check the boxes for:
- "Let users verify their identity with a built-in authenticator such as Touch ID or Windows Hello."
- "Let users verify their identity with a physical security key (U2F or WebAuthn)"
- (Optional) "Allow passwordless login with passkeys", which skips the MFA code entry.
- Click Save.
User registration
Each affected user then has to:
- Go to their Settings.
- Open Advanced User Details.
- In the Built-in Authenticators related list, click Register.
- Follow the prompts and give the authenticator a descriptive name, something like "Work Laptop - Dell XPS".
- If the passkey is going into a password manager, check the manager meets Salesforce's security requirements. Register the native device authenticator, Windows Hello for example, before the password manager.
- To add a secondary authenticator for a different device, repeat steps 3-5.
Then log in from a different browser and confirm you get the passkey prompt.
Managing access and rollout considerations
- Administrator lockout: make sure at least one other Salesforce Administrator can unlock your account. If you are locked out, Salesforce Support can issue a one-time code login, but do not count on it being immediate.
- The "Login As" feature: administrators who use it have to set up passkeys too.
- Multiple devices: for users who need access on several PCs without sharing passkey information or hardware tokens, register extra authenticators. Mobile devices link by scanning a QR code shown during registration.
- Rollout planning: mass registration takes time and communication, so coordinate with users and build in a check that they have actually added their authenticators.
Leave a Comment