Why Privileged Salesforce Users Are Getting Locked Out of the Mobile App (And What Actually Fixes It)

If you're a Salesforce admin or another privileged user with phishing-resistant MFA enforced, and you can log in fine from a browser but the native Salesforce mobile app won't let you in — you're not imagining it, and it's not a simple "register another passkey" fix. Here's what's actually going on, based on what we found working a live case with Salesforce support.

The symptom

  • Browser login (desktop or mobile Safari) works normally with your authenticator.
  • The native Salesforce mobile app fails during identity verification, often with an error suggesting no built-in authenticators are available.
  • This tends to show up specifically for privileged users — admins and others required to use phishing-resistant MFA — while non-privileged users on the same org log in without issue.

We're not the first to notice the general pattern of "app breaks, browser doesn't." But the specific mechanisms below don't appear to be documented anywhere else yet, including in otherwise thorough community FAQ roundups on Salesforce MFA issues.

What it's not

You may see advice suggesting the issue is a hard limit of one built-in authenticator (passkey/security key) per Salesforce account. This is not accurate. Salesforce has confirmed in writing, on our support case, that this is not a real platform limitation. Registering multiple passkeys or security keys on an account works fine in general — the actual cause is narrower than that.

What's actually happening

Two distinct mechanisms are in play:

1. A hidden "Login for Admin" option. Within the identity verification flow, there's a gear-icon option that surfaces an admin-specific login path — easy to miss on first pass because it isn't visually prominent. For privileged users hitting the standard verification wall, this option can be the way through.

2. A single-slot limit on Security Keys, specific to the mobile app. Within the native app's login flow specifically, the Security Key (U2F/WebAuthn) slot only supports one active entry at a time. This is different from the general claim above — it's not that you're limited to one authenticator on your account overall, it's that the mobile app's login flow itself only recognizes one Security Key entry. If you're relying on a physical security key and also want mobile app access, that single slot forces a choice unless you route around it another way (e.g., a different authenticator method for the app specifically).

The practical takeaway

If you manage a Salesforce org with phishing-resistant MFA enforced for admins or other privileged roles, and those users can't get into the mobile app:

  • Don't assume it's an unfixable one-authenticator-per-account limitation — it isn't.
  • Check for the gear-icon "Login for Admin" path during verification before escalating further.
  • If a physical security key is involved, be aware the mobile app's login flow only honors one Security Key slot — this is separate from how many passkeys the account can hold overall.
  • If neither resolves it, this is worth raising directly with Salesforce support as a reproducible issue affecting privileged/MFA-enforced users specifically, since it's a gap in how the mobile app handles identity verification for that user tier — not a configuration problem on your end.

We'll update this post if Salesforce ships a cleaner fix. In the meantime, if you're an admin fighting this exact issue, hopefully this saves you the runaround we went through.

Where does your business stand?

Take the Succession Readiness Scorecard

A free 5-minute assessment that scores your family business on the 7 principles of CRM-ready succession.

Take the Scorecard Book a consult