Update (September 2026): Since publishing this post, Salesforce has retracted the claim that built-in authenticators are limited to one per account — this was confirmed in writing on our support case. That means the root cause described below is not accurate, and following the workaround as originally written may not resolve the issue for everyone experiencing it.
We've since identified two more precise mechanisms behind these lockouts — including a hidden admin login option and a genuine single-slot limitation specific to the mobile app's Security Key flow — in a new, more accurate post: [Why Privileged Salesforce Users Are Getting Locked Out of the Mobile App (And What Actually Fixes It)]. We recommend reading that post instead of relying on the workaround below.
We're leaving the original post up for transparency and are correcting it because we'd rather someone learn the accurate fix from us than run into a dead end following outdated advice.
Here's What to Do:
If a built-in authenticator on Salesforce — Windows Hello, Touch ID, or similar — suddenly stopped being recognized and locked someone out, you're not dealing with a one-off glitch. This is a known, widespread problem tied to Salesforce's phishing-resistant MFA (PRMFA) enforcement rollout. Customers with registered built-in authenticators are finding their passkey becomes unrecognizable without warning, and Salesforce's Support queues and phone lines are under significant volume right now because of it.
One detail worth flagging directly: Salesforce Support has confirmed built-in authenticators (Touch ID, Windows Hello, and similar) are limited to one per account — not multiple. If your admins registered a built-in authenticator on their laptop, they can't also register one on a second device under that same method. That's not a bug; it's how the feature is designed. The redundancy admins actually need has to come from a different method entirely.
If this has hit your org, here's exactly what to do — and what not to waste time on.
This is the fast path, and it usually resolves in minutes:
This is the harder scenario, and speed depends on how you contact Support:
Given current support volume, a written case with "all admins locked out" noted is the fastest path available. Calling in and waiting on hold is not.
Two specific changes are known triggers, and both are worth ruling out first:
If either of those happened recently, that's very likely your answer — and it tells you exactly which users are at risk of hitting this next.
Here's the part worth correcting: a second built-in authenticator was never the redundancy plan to begin with — Salesforce only allows one per account. The real backup is a physical security key (YubiKey, Titan, etc.). Unlike a built-in authenticator, which is tied to one device's hardware, a physical key's credential lives on the key itself, so it works across any machine you plug it into — and it's not limited to one-per-account the way built-in authenticators are. If an admin's built-in authenticator ever stops being recognized, a registered physical key is what keeps them from being locked out entirely.
Given that, treat these as non-negotiable rather than nice-to-haves:
We'd still recommend registering a physical security key as a second, different-type method alongside your built-in authenticator — not another built-in authenticator, since Salesforce only allows one of those. A temporary verification code from another admin is still your immediate fallback if you get locked out before that's in place.
Salesforce now requires phishing-resistant MFA (a passkey or physical security key) for anyone with System Administrator profile or elevated permissions (Modify All Data, View All Data, Customize Application, Author Apex). But Salesforce's own documentation confirms passkey authentication — including both built-in authenticators and physical security keys — works for browser-based logins only and is not supported inside the native mobile app. Salesforce Authenticator and third-party TOTP apps no longer satisfy the requirement for admins either.
Put together, that means an admin's required method doesn't work in the app, and their fallback method has been disqualified. We tested this directly: a fully connected Salesforce Authenticator registration still gets rejected by the app for an admin account, because policy correctly overrides it.
The workaround, and its limits: logging in through your phone's browser instead of the app does work, but only if your passkey is portable. That means either a physical security key (which you carry with you and can tap or plug into any device), or a passkey saved to a synced vault such as iCloud Keychain, Google Password Manager, or a cross-platform manager like 1Password or Bitwarden.
Here's the catch: on a Windows laptop, registering a passkey typically defaults straight to Windows Hello (PIN or biometric) with no prompt to save it anywhere else. Unless a password manager is specifically set up to intercept that step, the passkey is locked to that one laptop and won't appear when you open a browser on your phone. We've seen this firsthand with several client setups — users were only ever shown the Windows Hello PIN option, nothing else.
If that's your situation, the mobile browser workaround won't help. The real fix is either adding a physical security key you carry, or deliberately setting up a synced passkey provider before you need it on the go — not after.
Sources: Salesforce Help — Troubleshoot Login Problems in Salesforce Mobile App, Salesforce Help — Phishing-Resistant MFA Enforcement for Privileged Users, Corbado — Device-Bound vs. Synced Passkeys
This is happening because of an active enforcement rollout, not a bug you caused. But "not your fault" doesn't mean "not worth fixing properly" — if one admin got locked out this way, there's a good chance others on your team are one domain change or device wipe away from the same thing.
If you're stuck in this right now, or want your org checked before it happens to someone else, reach out to our team. We can get a case escalated correctly if you're fully locked out, or walk your team through the disconnect-and-re-register fix if you still have admin access.
Reach out at philip@aeyecrm.com or through aeyecrm.com/contact.
About AeyeCRM
AeyeCRM — CRM, Workflow & Sales Automation, built on The 7 Principles — helps small and family-operated businesses get more out of Salesforce without overcomplicating it, including the security and identity issues that show up when the platform changes underneath them.