Skip to main content
New tool CRON Expression Builder — preview next run times before you schedule Apex. Open the builder →
A 3D rendered digital key symbolizing Salesforce passkey requirements for enhanced security.
Admin

Salesforce Passkeys: Admin Guide to User Requirements

Passkeys become mandatory for administrators and users with elevated permissions on July 1, 2026. Here is who gets caught by it, and how to get the new requirements in place before the rollout reaches you.

The short answer

Salesforce will require passkeys for administrators and for users holding certain elevated permissions, with production rollout starting July 1, 2026. The point is to shut down push bombing attacks by requiring physical presence at the device during login.

Key takeaways Passkeys are mandatory for admins and users with elevated permissions from July 2026. Find the affected users with a SOQL query against permissions like View All Data or Modify All Data. Users can pick device-bound passkeys using biometrics, or hardware security keys. Set it up under Setup > Identity > Identity Verification, then have each user register under Advanced User Details. Plan the rollout, keep an admin route back into the org, and check that users have complied.

Salesforce is going to require passkeys for administrators and for users who hold certain elevated permissions. Production rollout starts July 1, 2026. The aim is to shut down "push bombing" attacks by requiring physical presence at the device during login.

Background

Traditional multi-factor authentication can be worn down by an attacker firing login request after login request at a user's device until someone taps approve. Passkeys use device biometrics such as Touch ID or Windows Hello, or a hardware security key like a YubiKey, so there is stronger assurance that the user is actually at the machine.

Key dates

  • Sandbox rollout begins June 22, 2026, and runs for seven days.
  • Production rollout begins July 1, 2026, and runs for 30 days.

Who is affected?

Passkeys become mandatory for:

  • Users with administrator-level access.
  • Users with permissions such as Modify All Data, View All Data, Customize Application, or Author Apex.

Go through your Profiles and Permission Sets properly before you assume you know the list. Older orgs in particular tend to have handed out broad data visibility to people nobody thinks of as admins.

Identifying affected users with SOQL

This SOQL query pulls the users with the relevant permissions:

SELECT
    Assignee.Id,
    Assignee.Name,
    Assignee.Email,
    Assignee.Username,
    Assignee.IsActive,
    PermissionSet.Name,
    PermissionSet.Profile.Name,
    PermissionSet.PermissionsModifyAllData,
    PermissionSet.PermissionsViewAllData,
    PermissionSet.PermissionsCustomizeApplication,
    PermissionSet.PermissionsAuthorApex
FROM
    PermissionSetAssignment
WHERE
    Assignee.IsActive = TRUE
    AND (
        PermissionSet.PermissionsModifyAllData = TRUE
        OR PermissionSet.PermissionsViewAllData = TRUE
        OR PermissionSet.PermissionsCustomizeApplication = TRUE
        OR PermissionSet.PermissionsAuthorApex = TRUE
    )

It returns every active user assigned to a permission set carrying those elevated permissions, whether the permission came from a Profile or a Permission Set.

Passkey options

Users get a choice here.

Device-bound passkeys tie to a PC, Mac, or mobile app and use biometrics. They are free. The catch is that they need cloud backup, or the user is locked out when the primary device is not around. Be careful about leaning on a password manager if it does not meet Salesforce's current security criteria.

Security keys are physical USB tokens. They are device agnostic, which suits anyone who switches machines or does not always carry a laptop. They are one more thing to lose, and they carry a recurring cost of roughly $35 USD per user.

Registering both is worth recommending to users with several devices, or anyone who wants a backup option.

Implementation steps

Administrator setup

  1. Go to Setup > Identity > Identity Verification.
  2. Check the boxes for:
    • "Let users verify their identity with a built-in authenticator such as Touch ID or Windows Hello."
    • "Let users verify their identity with a physical security key (U2F or WebAuthn)"
    • (Optional) "Allow passwordless login with passkeys", which skips the MFA code entry.
  3. Click Save.

User registration

Each affected user then has to:

  1. Go to their Settings.
  2. Open Advanced User Details.
  3. In the Built-in Authenticators related list, click Register.
  4. Follow the prompts and give the authenticator a descriptive name, something like "Work Laptop - Dell XPS".
  5. If the passkey is going into a password manager, check the manager meets Salesforce's security requirements. Register the native device authenticator, Windows Hello for example, before the password manager.
  6. To add a secondary authenticator for a different device, repeat steps 3-5.

Then log in from a different browser and confirm you get the passkey prompt.

Managing access and rollout considerations

  • Administrator lockout: make sure at least one other Salesforce Administrator can unlock your account. If you are locked out, Salesforce Support can issue a one-time code login, but do not count on it being immediate.
  • The "Login As" feature: administrators who use it have to set up passkeys too.
  • Multiple devices: for users who need access on several PCs without sharing passkey information or hardware tokens, register extra authenticators. Mobile devices link by scanning a QR code shown during registration.
  • Rollout planning: mass registration takes time and communication, so coordinate with users and build in a check that they have actually added their authenticators.

Originally reported by salesforceben.com

Newsletter

One email every Tuesday

New guides, tool updates, and the release-note changes that break things.

No spam. Unsubscribe in one click.

Comments

Loading comments...

Leave a Comment