If your Account Administrator has allowed the use of security keys for Web
Authentication (WebAuthn), you can register your FIDO2-compliant U2F security key to connect
it to your account. Anytime you’re challenged to verify your identity, including
multi-factor authentication (MFA) and device activations, you can insert your security key
into the appropriate port on your computer or mobile device to complete verification. You
can register the same security key with multiple service providers and multiple Salesforce
orgs and accounts. You can also register one key per account.
Have your FIDO2-compliant U2F security key in hand so that you’re ready to insert
it when prompted. If you wait too long, your registration attempt can time out. To
register a security key:
-
How you proceed depends on the MFA verification method settings of your
organization:
- If WebAuthn Identity Verification is your only available multi-factor
authentication (MFA) verification method, you are prompted to insert the
security key at your next login. You can proceed to the next step.
- If WebAuthn Identity Verification or another multi-factor authentication
(MFA) verification method are available to you, you are prompted to
insert the security key at your next login. Click Security
Key and proceed to the next step.
- If you are logged into Account Manager, and if multiple MFA verification
methods are available, you can connect a security key for WebAuthn
Identity Verification in your Account Information. Click
Add next to Multi-Factor
Verification and choose Security
Key and proceed to the next step.
-
At the prompt, insert your security key into the appropriate port on your
computer or mobile device. If it has a button, touch the button.
Security keys aren’t a biometric device, even though some have a button that requires your touch to activate the device.
-
Click Continue to dismiss the confirmation
message.
Now you’re ready to use this identity verification method. Your security key
generates the required credentials, and the browser passes them on to
Salesforce to complete the verification. To help keep your account secure,
we send you an email notification whenever a new identity verification
method is added to your Account Manager account.