Admin: Salesforce MFA and Phishing-Resistant MFA Enforcement

Salesforce is enforcing stronger authentication requirements across all organizations. This includes MFA enforcement for all users logging in via direct UI or SSO, and phishing-resistant MFA requirement for users with the System Administrator profile or with Modify All Data, View All Data, Customize Application, or Author Apex permissions.

Background

Two related Salesforce changes are relevant to your organization:

  1. General MFA enforcement for all users (direct logins and SSO)
  2. Phishing-resistant MFA enforcement specifically for privileged and admin users (System Administrator profile, or users with Modify All Data, View All Data, Customize Application, or Author Apex permissions)

For SSO logins, Salesforce doesn't just verify that MFA occurred—it inspects specific authentication signals passed by the identity provider (IdP) to determine which tier of assurance was used: Phishing-Resistant MFA, Standard MFA, or Weak/No MFA. If a phishing-resistant-tier signal isn't present, Salesforce will block the login until the user enrolls a compliant method directly in Salesforce.

What You Should Verify

Salesforce's enforcement is Org-wide. Bullhorn recommends you confirm the following:

Admin and Privileged User Authentication

Your own internal admins and privileged users (those with the System Administrator profile or one or more of the following permissions: Modify All Data, View All Data, Customize Application, or Author Apex) must have a compliant phishing-resistant method registered, or your identity provider must be passing an equivalent phishing-resistant AMR/ACR signal for them.

Compliant phishing-resistant methods include:

  • Passkey
  • Security key
  • Windows Hello
  • Touch ID/Face ID

Bullhorn recommends setting up at least 2 phishing resistant methods to avoid getting locked out when changing or losing devices.

Exempted Service and Test Accounts

Review any exempted service accounts, automation accounts, or test accounts. Salesforce's Waive Multi-Factor Authentication for Exempt Users permission no longer auto-exempts accounts after enforcement begins. You may need to re-configure exemptions for these accounts.

How the Bullhorn Administrator User Meets This Requirement

Bullhorn's SSO infrastructure passes the swk AMR value on logins for the Bullhorn Administrator User. swk denotes proof-of-possession of a software-secured key, which is one of the values Salesforce classifies in the Phishing-Resistant MFA tier of its AMR signal list.

No action is required from you regarding the Bullhorn Administrator User specifically. Its logins already satisfy Salesforce's phishing-resistant MFA requirement.

Related Resources

For additional information and the full list of accepted authentication strength tiers, refer to Salesforce's official documentation: