Here's What to Do:
If a built-in authenticator on Salesforce — Windows Hello, Touch ID, or similar — suddenly stopped being recognized and locked someone out, you're not dealing with a one-off glitch. This is a known, widespread problem tied to Salesforce's phishing-resistant MFA (PRMFA) enforcement rollout. Customers with registered built-in authenticators are finding their passkey becomes unrecognizable without warning, and Salesforce's Support queues and phone lines are under significant volume right now because of it.
One detail worth flagging directly: this isn't limited to wiping out a single registered passkey. We've seen accounts where every built-in authenticator registered on the account got wiped out at once — not just the one the user happened to be using. If your admins registered two or three built-in authenticators thinking that gave them redundancy, this issue can take all of them out simultaneously, since they're the same method type.
If this has hit your org, here's exactly what to do — and what not to waste time on.
This is the fast path, and it usually resolves in minutes:
This is the harder scenario, and speed depends on how you contact Support:
Given current support volume, a written case with "all admins locked out" noted is the fastest path available. Calling in and waiting on hold is not.
Two specific changes are known triggers, and both are worth ruling out first:
If either of those happened recently, that's very likely your answer — and it tells you exactly which users are at risk of hitting this next.
Here's the part that makes this issue worse than a typical device problem: registering a built-in authenticator on more than one device doesn't reliably protect you against it. We've seen accounts where every built-in authenticator was wiped at once, including ones registered on separate devices. That's not a local browser or OS problem — that's the account-level record on Salesforce's side getting cleared, which means the usual advice ("just register a backup device") doesn't hold up here.
Given that, treat these as non-negotiable rather than nice-to-haves:
We'd still register a backup device and turn on cloud sync where available — they're good practice for ordinary device loss or OS reinstalls. Just don't count on them as protection against this specific bug. Right now, a human with temp-code access is the only backup that's held up.
This is happening because of an active enforcement rollout, not a bug you caused. But "not your fault" doesn't mean "not worth fixing properly" — if one admin got locked out this way, there's a good chance others on your team are one domain change or device wipe away from the same thing.
If you're stuck in this right now, or want your org checked before it happens to someone else, reach out to our team. We can get a case escalated correctly if you're fully locked out, or walk your team through the disconnect-and-re-register fix if you still have admin access.
Reach out at philip@aeyecrm.com or through aeyecrm.com/contact.
About AeyeCRM
AeyeCRM — CRM, Workflow & Sales Automation, built on The 7 Principles — helps small and family-operated businesses get more out of Salesforce without overcomplicating it, including the security and identity issues that show up when the platform changes underneath them.