Here's What to Do:
If a built-in authenticator on Salesforce — Windows Hello, Touch ID, or similar — suddenly stopped being recognized and locked someone out, you're not dealing with a one-off glitch. This is a known, widespread problem tied to Salesforce's phishing-resistant MFA (PRMFA) enforcement rollout. Customers with registered built-in authenticators are finding their passkey becomes unrecognizable without warning, and Salesforce's Support queues and phone lines are under significant volume right now because of it.
One detail worth flagging directly: Salesforce Support has confirmed built-in authenticators (Touch ID, Windows Hello, and similar) are limited to one per account — not multiple. If your admins registered a built-in authenticator on their laptop, they can't also register one on a second device under that same method. That's not a bug; it's how the feature is designed. The redundancy admins actually need has to come from a different method entirely.
If this has hit your org, here's exactly what to do — and what not to waste time on.
If another admin can still log in
This is the fast path, and it usually resolves in minutes:
- Go to Setup → Users and find the locked-out user
- Either generate a one-time temporary verification code to get them back in immediately, or disconnect the broken built-in authenticator so it stops blocking a fresh registration
- Once access is restored, have the user register a brand-new passkey rather than trying to repair the old one
If ALL admins are locked out
This is the harder scenario, and speed depends on how you contact Support:
- Open a case in writing — don't rely on the phone right now given call volume
- Explicitly state "all admins locked out" in the case. That phrase flags it for priority handling
- Salesforce's Support team can use backend access to delete the broken built-in authenticator credential on their end, which lets the admin log back in and register a new one
- If the Help Portal itself isn't reachable because the org is fully locked out, go through your CSM or Account Executive — they can route the case directly to the Security & Activations swarm team
Given current support volume, a written case with "all admins locked out" noted is the fastest path available. Calling in and waiting on hold is not.
Two questions worth checking before you assume it's a mystery
Two specific changes are known triggers, and both are worth ruling out first:
- Did the org recently have a My Domain change or a sandbox refresh? Passkeys are domain-bound. When the domain changes, previously registered passkeys break.
- Did the affected user's browser profile get reset, or was their device wiped? Either one clears the saved credential the built-in authenticator relies on.
If either of those happened recently, that's very likely your answer — and it tells you exactly which users are at risk of hitting this next.
Multiple devices didn't protect against this — and that matters
Here's the part worth correcting: a second built-in authenticator was never the redundancy plan to begin with — Salesforce only allows one per account. The real backup is a physical security key (YubiKey, Titan, etc.). Unlike a built-in authenticator, which is tied to one device's hardware, a physical key's credential lives on the key itself, so it works across any machine you plug it into — and it's not limited to one-per-account the way built-in authenticators are. If an admin's built-in authenticator ever stops being recognized, a registered physical key is what keeps them from being locked out entirely.
Given that, treat these as non-negotiable rather than nice-to-haves:
- At least one other admin who can generate a temporary verification code. This is currently the only reliable safety net, because it's issued fresh at the time of the lockout and doesn't depend on any previously registered credential surviving.
- When you open a Support case, say explicitly that every built-in authenticator on the account was wiped simultaneously, including ones on separate devices. That's a stronger, more specific signal than "my passkey stopped working," and it's worth putting in writing so Salesforce can see the pattern rather than treating it as a single-device issue.
We'd still recommend registering a physical security key as a second, different-type method alongside your built-in authenticator — not another built-in authenticator, since Salesforce only allows one of those. A temporary verification code from another admin is still your immediate fallback if you get locked out before that's in place.
A separate issue worth knowing about: the Salesforce mobile app currently has no working MFA path for admins.
Salesforce now requires phishing-resistant MFA (a passkey or physical security key) for anyone with System Administrator profile or elevated permissions (Modify All Data, View All Data, Customize Application, Author Apex). But Salesforce's own documentation confirms passkey authentication — including both built-in authenticators and physical security keys — works for browser-based logins only and is not supported inside the native mobile app. Salesforce Authenticator and third-party TOTP apps no longer satisfy the requirement for admins either.
Put together, that means an admin's required method doesn't work in the app, and their fallback method has been disqualified. We tested this directly: a fully connected Salesforce Authenticator registration still gets rejected by the app for an admin account, because policy correctly overrides it.
The workaround, and its limits: logging in through your phone's browser instead of the app does work, but only if your passkey is portable. That means either a physical security key (which you carry with you and can tap or plug into any device), or a passkey saved to a synced vault such as iCloud Keychain, Google Password Manager, or a cross-platform manager like 1Password or Bitwarden.
Here's the catch: on a Windows laptop, registering a passkey typically defaults straight to Windows Hello (PIN or biometric) with no prompt to save it anywhere else. Unless a password manager is specifically set up to intercept that step, the passkey is locked to that one laptop and won't appear when you open a browser on your phone. We've seen this firsthand with several client setups — users were only ever shown the Windows Hello PIN option, nothing else.
If that's your situation, the mobile browser workaround won't help. The real fix is either adding a physical security key you carry, or deliberately setting up a synced passkey provider before you need it on the go — not after.
Sources: Salesforce Help — Troubleshoot Login Problems in Salesforce Mobile App, Salesforce Help — Phishing-Resistant MFA Enforcement for Privileged Users, Corbado — Device-Bound vs. Synced Passkeys
Don't wait for the next one
This is happening because of an active enforcement rollout, not a bug you caused. But "not your fault" doesn't mean "not worth fixing properly" — if one admin got locked out this way, there's a good chance others on your team are one domain change or device wipe away from the same thing.
If you're stuck in this right now, or want your org checked before it happens to someone else, reach out to our team. We can get a case escalated correctly if you're fully locked out, or walk your team through the disconnect-and-re-register fix if you still have admin access.
Reach out at philip@aeyecrm.com or through aeyecrm.com/contact.
About AeyeCRM
AeyeCRM — CRM, Workflow & Sales Automation, built on The 7 Principles — helps small and family-operated businesses get more out of Salesforce without overcomplicating it, including the security and identity issues that show up when the platform changes underneath them.