Salesforce Authenticator provides two-factor authentication (2FA) to protect your Salesforce account with push notifications and location-based security. This guide covers setup, configuration, and advanced features for secure access.
Salesforce Authenticator works by requiring two authentication factors:
- Something You Know: Your Salesforce username and password
- Something You Have: Your mobile device with the Salesforce Authenticator app
When you log in to Salesforce, the system sends a push notification to your mobile device. You review the login details (location, device, time) and approve or deny the request. The app can also recognize trusted locations like your office for streamlined authentication.
What is Multi-Factor Authentication in Salesforce
Multi-Factor Authentication (MFA) requires at least two pieces of evidence to verify your identity. Salesforce mandates MFA for all users accessing production orgs as of February 2022.
- First factor: Username and password credentials
- Second factor: Verification method you possess (mobile device with security app)
This layered approach protects against password breaches because attackers need both your credentials and physical access to your verification device. Salesforce Authenticator is the recommended MFA method for its speed and reliability.
How to Download and Install Salesforce Authenticator
Setting up Salesforce Authenticator requires downloading the mobile app and connecting it to your Salesforce account.
Step 1: Download the App
- Download from Apple App Store for iOS devices
- Download from Google Play Store for Android devices
Step 2: Install and Open the App
- Install the app following standard device installation procedures
- Open Salesforce Authenticator and complete the initial setup tour
- Grant necessary permissions for notifications and location services
Registering Salesforce Authenticator with Your Account
Connect the mobile app to your Salesforce org through the registration process:
Step 1: Access Salesforce Login
- Log in to your Salesforce org through your web browser
- Enter your username and password as normal
- The system prompts for MFA verification
Step 2: Select Salesforce Authenticator
- Choose Salesforce Authenticator from the verification method options
- Click Continue to proceed with setup
Step 3: Connect Mobile App
- In the mobile app, tap Add an Account
- The app displays a unique two-word phrase
- Enter this phrase in your Salesforce browser session
- Review the connection request details in the mobile app
- Tap Confirm to establish the connection
The registration process creates a secure connection between your Salesforce org and the mobile app for future authentication requests.
Configuring Account Backups for Security
Enable account backups to restore your Salesforce Authenticator configuration if you lose or replace your mobile device:
Step 1: Verify Email Address
- Tap the settings icon in Salesforce Authenticator
- Select Backup Accounts
- Enter your email address for verification
- Check your email and enter the verification code
Step 2: Set Backup Passcode
- Create a secure passcode for backup restoration
- Store this passcode securely – you’ll need it to restore accounts
Account backups encrypt your Salesforce Authenticator data and store it securely. This feature prevents lockouts when changing devices or after factory resets.
Enabling Push Notifications for MFA
Configure push notifications to receive instant login approval requests:
Step 1: App Notification Settings
- Open Salesforce Authenticator settings
- Verify push notifications are enabled
- If disabled, tap Change to modify settings
Step 2: Device Permission Settings
- Access your device’s main settings menu
- Navigate to app permissions for Salesforce Authenticator
- Enable notification permissions
- Allow background app refresh for timely notifications
Push notifications deliver login requests instantly, reducing authentication delays and improving user experience.
Salesforce Authenticator Login Process
The standard login flow with Salesforce Authenticator follows these steps:
Step 1: Enter Salesforce Credentials
- Navigate to your Salesforce login page
- Enter your username and password
- Click Log In
Step 2: Receive Push Notification
- Salesforce sends a push notification to your registered device
- The notification appears on your lock screen or notification panel
Step 3: Review Login Details
- Open the Salesforce Authenticator app
- Verify the login attempt details:
- Username matches your login attempt
- Service field shows correct Salesforce org
- Device and browser information is accurate
- Location matches your current location
Step 4: Approve or Deny Access
- Tap Approve if all details are correct
- Tap Deny if anything appears suspicious
- The browser session completes login or blocks access accordingly
Always verify login details before approving. Deny any requests with unfamiliar locations, devices, or timing.
Advanced Salesforce Authenticator Features
Salesforce Authenticator includes advanced features for enhanced security and convenience:
Automatic Approval for Trusted Locations
- Configure trusted locations (office, home) in app settings
- Enable automatic approval for logins from these locations
- The app uses GPS and network data to verify location
- Automatic approval only works when all login details match expected patterns
Einstein AI Recommendations
- Enable Einstein recommendations in automation settings
- AI analyzes your login patterns and suggests trusted requests
- Recommendations consider time, location, device, and frequency
- Review AI suggestions before enabling automatic approval
One-Time Passcodes (TOTP)
- Generate time-based one-time passcodes when push notifications fail
- Use passcodes during network connectivity issues
- Passcodes refresh every 30 seconds
- Enter the current passcode in the Salesforce MFA prompt
Multiple Account Support
- Connect multiple Salesforce orgs to one Authenticator app
- Each org appears as a separate account in the app
- Manage production, sandbox, and developer orgs from one device
Salesforce Authenticator Security Best Practices
Follow these security practices to maximize protection:
Device Security
- Enable device lock screen with PIN, password, or biometric authentication
- Keep your mobile device updated with latest security patches
- Avoid installing Salesforce Authenticator on jailbroken or rooted devices
App Management
- Regularly review connected accounts in app settings
- Remove old or unused Salesforce org connections
- Update the app when new versions are available
Monitoring and Response
- Monitor login notifications for suspicious activity
- Report denied login attempts to your Salesforce administrator
- Change your Salesforce password if you suspect compromise
Troubleshooting Common Issues
Push Notifications Not Received
- Check device notification permissions for Salesforce Authenticator
- Verify network connectivity (WiFi or cellular data)
- Restart the app and try logging in again
- Use one-time passcode as backup authentication method
App Connection Issues
- Re-register the app if connection fails repeatedly
- Clear app cache and data (Android) or reinstall (iOS)
- Contact your Salesforce admin to reset MFA settings
Device Replacement
- Use account backup to restore connections on new device
- Contact Salesforce support if backup restoration fails
- Admin can temporarily disable MFA for account recovery
Frequently Asked Questions
What happens if I lose my phone with Salesforce Authenticator?
If you enabled account backups, download Salesforce Authenticator on your new device and restore your accounts using your backup email and passcode. If you didn’t enable backups, contact your Salesforce administrator to temporarily disable MFA so you can log in and reconfigure authentication.
Can I use Salesforce Authenticator for multiple Salesforce orgs?
Yes, you can connect multiple Salesforce orgs to one Salesforce Authenticator app. Each org appears as a separate account in the app. This includes production orgs, sandboxes, and developer editions.
Does Salesforce Authenticator work without internet connection?
Push notifications require internet connectivity, but Salesforce Authenticator can generate time-based one-time passcodes (TOTP) that work offline. Use these 6-digit codes in the MFA prompt when push notifications aren’t available.
How secure is Salesforce Authenticator compared to SMS codes?
Salesforce Authenticator is more secure than SMS-based authentication. SMS codes can be intercepted through SIM swapping or network attacks. Salesforce Authenticator uses encrypted push notifications and doesn’t rely on cellular networks for code delivery.
Can I disable automatic approval for trusted locations?
Yes, you can disable automatic approval in the Salesforce Authenticator settings. Navigate to automation settings and turn off trusted location features. You’ll receive push notifications for all login attempts regardless of location.
Conclusion
Salesforce Authenticator provides robust two-factor authentication for Salesforce accounts through push notifications, location awareness, and backup features. Proper setup and configuration ensure secure access while maintaining user convenience. Regular monitoring and following security best practices maximize protection against unauthorized access attempts.