top of page

User Operation Instructions for Salesforce MFA (FIDO2 / U2F)

This section describes how to register a security key (FIDO2 / U2F) and how to log in.

2022/06/15 Article update

By supporting WebAuthn (FIDO2) in ​Salesforce, registration and authentication methods using FIDO2 compatible security keys have been added.

​How to set and initialize FIDO2 compatible keysherePlease refer to

News

2022/06/12
By applying the Summer'22 version of Salesforce,Supports WebAuthn (FIDO2) security keysI came to This change allows users to register WebAuthn (FIDO2) or U2F security keys for identity verification. If you have keys previously registered as FIDO U2F, you may be prompted for an authentication sequence (PIN) as FIDO2 due to Summer'22 enforcement.

Environmental information

Device: Windows 10

​ Interface: Lightning Experience

Browser: Chrome

​ *Depending on the OS and browser you use, it may differ from the explanation image.

Security key registration method

This section describes how to register a security key (FIDO2 / U2F) by the user.

​​If the system administrator has set MFA (multi-factor authentication) for the user, the user will be required to register a security key at the next login. increase.

Log in with "username/password" from the login page of Salesforce.

2021-11-08_14h31_43-min.jpg

Connect Salesforce Authenticator Click "Choose another verification method" at the bottom of the screen.

2021-11-08_14h40_22-min.jpg

Click Use Universal Second Factor (U2F) Key or WebAuthn (FIDO2) and click Next.

2022-06-15_11h42_32.png

Click the "Register" button on the Register Security Key page.

2022-06-15_11h45_37.png

After moving to the security key registration page, the "Security key setup" popup will automatically appear, so click the "OK" button.

2022-06-14_16h01_17.png

Next, "Continue Setup" will be displayed, so click the "OK" button.

2022-06-14_16h01_25.png

Insert the security key into the USB port.

2022-06-14_16h01_36.png

For registration with FIDO2 security key

For FIDO2-compatible security keys, you will be prompted to enter a PIN.

​If a PIN has not been set for the security key, a screen for setting will be displayed. Please set a PIN.

2022-06-14_16h01_46.png

Touch the button or metal part of the security key.

2022-06-14_16h03_11.png

Finally, enter the security key name and click the "Save" button to complete security key registration and login.

*For both FIDO2 / U2F, the flow is to set the security key name after completing the registration.

2022-06-14_16h03_21.png

​From the next login, you will be asked to authenticate with the security key after logging in with your "user name/password".

セキュリティキーの登録方法

How to log in with a security key

Describes how users log in with security keys (U2F).

​The user must have registered a security key.

​Regarding how to register "Security key registration methodPlease refer to

From the login page of Salesforce, log in with "user name / password".

2021-11-08_14h31_43-min.jpg

Click the Validate button.

2022-06-15_12h59_54.png

Insert the security key into the USB port.

2022-06-15_13h06_31.png

After that, the authentication sequence differs between FIDO2 compatible security keys and FIDO U2F only compatible security keys.

Here's a quick way to tell.

U2F: Authentication is completed just by touching the security key.

FIDO2: A PIN is required during authentication.
​ *If a PIN is not set for the security key, the PIN setting screen will be displayed.

For registration with FIDO U2F security key

For security keys that only support FIDO U2F, PIN is not required, and authentication is completed simply by touching the button or metal part of the security key.

2022-06-15_13h06_56.png

For authentication with FIDO2 security keys

For FIDO2-compatible security keys, you will be prompted to enter a PIN.

​If a PIN has not been set for the security key, a screen for setting will be displayed. Please set a PIN.

2022-06-15_13h06_51.png

Touch the button or metal part of the security key.

2022-06-15_13h06_56.png

You have successfully logged in.

2021-11-08_15h15_52-min.jpg
セキュリティキーでのログイン方法

If you lose or forget your security key

If you have lost or forgotten your security key, you can temporarily log in using a temporary code by contacting the system administrator and having them issue a verification code. Here, we explain what to do when the security key cannot be used and how to log in with the confirmation code.

If the security key cannot be used when logging in, the "lost security key"or"forgot security key” to the system administrator. After reporting, wait for contact from the system administrator.

When reporting to the system administrator, be sure to use the "lost" or "I forgotPlease clearly report whether

After receiving the confirmation code and expiration date from the system administrator, log in with "user name / password" from the login page of Salesforce.

2021-11-08_14h31_43-min.jpg

Enter the verification code provided by your system administrator and click the "Verify" button.

​*You cannot log in with an expired confirmation code.

2021-11-08_17h27_50-min.jpg

Login completed.

​ [For lost security key]

​Logging in with the verification code is only a temporary workaround. If you receive a new security key, please re-register as soon as possible.

セキュリティキーを紛失または忘れた場合

After that, the registration sequence differs between FIDO2-compatible security keys and FIDO U2F-only security keys.

Here's a quick way to tell.

U2F: Just touch the security key to complete setup.

FIDO2: A PIN is required during setup.
​ *If a PIN is not set for the security key, the PIN setting screen will be displayed.

For registration with FIDO U2F security key

For security keys that only support FIDO U2F, no PIN is required, and setup is completed simply by touching the button or metal part of the security key.

2022-06-14_16h03_11.png
bottom of page