Skip to main content

Setting Up Passkeys for Login Verification

Salesforce is introducing updated login security requirements that require System Administrators and users with certain elevated permissions to verify their identity using a passkey or built-in authenticator, such as Touch ID, Face ID, Windows Hello, a device PIN, or a physical security key.

This helps keep your data more secure while giving users a faster, easier way to verify their identity when logging in.

Admin Setup: Enable Passkey Login Options

A system admin will need to enable a few settings before users can register and use passkeys.

  1. Go to Setup > Identity Verification.

  2. Enable the following three settings:

    • Let users verify their identity with a built-in authenticator such as Touch ID or Windows Hello

    • Let users verify their identity with a physical security key (U2F or WebAuthn)

    • Allow passwordless login with passkeys

  3. Click Save.

Once these settings are enabled, users can register a built-in authenticator or passkey from their personal settings.

User Setup: Register a Built-In Authenticator or Passkey

If your org has already enabled MFA and you have not registered a verification method yet, you will be prompted to register one the next time you log in. Follow the onscreen instructions.

If you are already logged in, you can register one manually by following these steps:

  1. Go to your personal profile settings by clicking your avatar in the upper-right corner, then click Settings.

  2. Go to Advanced User Details.

  3. Scroll down to the Built-in Authenticators section and click Add.

    1. If you do not see this option, your Salesforce admin has not enabled built-in authenticators for your org yet.

    2. For security purposes, Rethink may ask you to log in again or verify your identity.

  4. When prompted, click Register.

  5. Your browser or device will ask you to verify using the method already set up on your device, such as:

    • Touch ID

    • Face ID

    • Windows Hello

    • Device PIN

    • Device password

    • Physical security key

  6. Complete the browser or device prompt.

  7. Give your built-in authenticator a recognizable name, such as “MacBook Touch ID” or “Windows Hello.”

  8. Click Save.

Your passkey or built-in authenticator is now registered and can be used for future login verification.

Did this answer your question?