Here's What to Do:
If a built-in authenticator on Salesforce — Windows Hello, Touch ID, or similar — suddenly stopped being recognized and locked someone out, you're not dealing with a one-off glitch. This is a known, widespread problem tied to Salesforce's phishing-resistant MFA (PRMFA) enforcement rollout. Customers with registered built-in authenticators are finding their passkey becomes unrecognizable without warning, and Salesforce's Support queues and phone lines are under significant volume right now because of it.
One detail worth flagging directly: this isn't limited to wiping out a single registered passkey. We've seen accounts where every built-in authenticator registered on the account got wiped out at once — not just the one the user happened to be using. If your admins registered two or three built-in authenticators thinking that gave them redundancy, this issue can take all of them out simultaneously, since they're the same method type.
If this has hit your org, here's exactly what to do — and what not to waste time on.
If another admin can still log in
This is the fast path, and it usually resolves in minutes:
- Go to Setup → Users and find the locked-out user
- Either generate a one-time temporary verification code to get them back in immediately, or disconnect the broken built-in authenticator so it stops blocking a fresh registration
- Once access is restored, have the user register a brand-new passkey rather than trying to repair the old one
If ALL admins are locked out
This is the harder scenario, and speed depends on how you contact Support:
- Open a case in writing — don't rely on the phone right now given call volume
- Explicitly state "all admins locked out" in the case. That phrase flags it for priority handling
- Salesforce's Support team can use backend access to delete the broken built-in authenticator credential on their end, which lets the admin log back in and register a new one
- If the Help Portal itself isn't reachable because the org is fully locked out, go through your CSM or Account Executive — they can route the case directly to the Security & Activations swarm team
Given current support volume, a written case with "all admins locked out" noted is the fastest path available. Calling in and waiting on hold is not.
Two questions worth checking before you assume it's a mystery
Two specific changes are known triggers, and both are worth ruling out first:
- Did the org recently have a My Domain change or a sandbox refresh? Passkeys are domain-bound. When the domain changes, previously registered passkeys break.
- Did the affected user's browser profile get reset, or was their device wiped? Either one clears the saved credential the built-in authenticator relies on.
If either of those happened recently, that's very likely your answer — and it tells you exactly which users are at risk of hitting this next.
Multiple devices didn't protect against this — and that matters
Here's the part that makes this issue worse than a typical device problem: registering a built-in authenticator on more than one device doesn't reliably protect you against it. We've seen accounts where every built-in authenticator was wiped at once, including ones registered on separate devices. That's not a local browser or OS problem — that's the account-level record on Salesforce's side getting cleared, which means the usual advice ("just register a backup device") doesn't hold up here.
Given that, treat these as non-negotiable rather than nice-to-haves:
- At least one other admin who can generate a temporary verification code. This is currently the only reliable safety net, because it's issued fresh at the time of the lockout and doesn't depend on any previously registered credential surviving.
- When you open a Support case, say explicitly that every built-in authenticator on the account was wiped simultaneously, including ones on separate devices. That's a stronger, more specific signal than "my passkey stopped working," and it's worth putting in writing so Salesforce can see the pattern rather than treating it as a single-device issue.
We'd still register a backup device and turn on cloud sync where available — they're good practice for ordinary device loss or OS reinstalls. Just don't count on them as protection against this specific bug. Right now, a human with temp-code access is the only backup that's held up.
Don't wait for the next one
This is happening because of an active enforcement rollout, not a bug you caused. But "not your fault" doesn't mean "not worth fixing properly" — if one admin got locked out this way, there's a good chance others on your team are one domain change or device wipe away from the same thing.
If you're stuck in this right now, or want your org checked before it happens to someone else, reach out to our team. We can get a case escalated correctly if you're fully locked out, or walk your team through the disconnect-and-re-register fix if you still have admin access.
Reach out at philip@aeyecrm.com or through aeyecrm.com/contact.
About AeyeCRM
AeyeCRM — CRM, Workflow & Sales Automation, built on The 7 Principles — helps small and family-operated businesses get more out of Salesforce without overcomplicating it, including the security and identity issues that show up when the platform changes underneath them.