Salesforce Just Made Passkeys Mandatory for Admins - Is Your Business Ready?
- joemills74
- Aug 12
- 2 min read

Are you a Salesforce Admin returning back from your summer leave?
Salesforce has quietly flipped a switch that could lock your admins out of their own system.
Since July 2026, any user with System Administrator access, or permissions like Modify All Data, View All Data, Customize Application, must authenticate using phishing-resistant methods - passkeys, physical security keys, or FIDO2-compliant password manager passkeys. The older authenticator app codes and SMS no longer count.
Why it matters: the setting can't be switched off, and anyone without a registered method gets blocked at login. That includes external consultants or partners with standing admin access to your org.
The catch admins are hitting: built-in authenticators like Windows Hello or Touch ID are tied to the specific device they were set up on. Register one on your office laptop, and your home laptop won't recognise it automatically! You have to add a second authenticator for that device too. Miss that step and you're locked out the moment you switch machines. It's common enough that admins have already been alerting to this issue and alongside a separate bug where previously-working authenticators stop being recognised without warning.
What to do:
Identify every privileged user. Check permission sets, not just profiles
Register a passkey on every device you actually use, not just one
Consider a FIDO2-compliant password manager (1Password, Bitwarden) - passkeys sync across devices automatically, sidestepping the device-lock issue entirely
Make sure a second admin can unlock any account that gets locked out
If a partner supports your org, check their access is a dedicated, passkey-secured login, not a shared one
Ten minutes of setup now beats a locked-out admin or a whole team stuck outside their own system.



Comments