Skip to main content

#Multi-Factor-Authentication6 utenti parlano di questo argomento

Hi everyone,  

 

I was wondering if anyone has experience adding multiple passkeys to the same user account.  

I have set up on key already with the password manager, but am trying to set up a second one on the phone only. The issue is the second attempt will say no matching passkeys found as it is already searching for existing.  

 

Alternatively, is it possbile to keep the passkey setup with the password manager, and add  a second physical security key in addition, and have the option to use either one of them? 

 

Thanks for the help!  

 

Marie Olsen 

 

#Login Attempt  #Multi-Factor-Authentication  #Security

2 risposte
  1. 15 ago, 19:47

    Hi Marie - yes, Salesforce supports registering more than one passkey/security key on the same account, and you can use any of them to log in. The behavior you're hitting is the classic passkey gotcha: adding a second one has to be done from the registration flow in your settings, not from the login screen. 

     

    Here's what's happening: at the login prompt, the browser/OS is trying to authenticate, so it searches for an existing passkey - that's the 'no matching passkeys found / searching for existing' message. That flow only looks for credentials already registered; it will never create a new one. So the second passkey has to be enrolled from inside your account. 

     

    To add another one: log in with your existing (password-manager) passkey, then go to your personal Settings and find the security-key / built-in-authenticator registration area (in Lightning it's under your personal Settings - look for Advanced User Details, which has the register links for a security key or built-in authenticator). Start the registration there, and when the passkey dialog appears, choose the new target - your phone, or 'use a different device' - rather than the saved password-manager one. That enrolls a second, independent credential. 

     

    On your alternative question: yes, you can absolutely keep the password-manager passkey and add a physical security key as well. Register the physical key the same way (from settings, not login), and at sign-in you can use whichever one you have on hand. Mixing a platform passkey with a roaming security key is exactly the kind of redundancy passkeys are meant to allow - having a backup method registered is a good idea. 

     

    One thing to watch: start each new registration from your account settings while you're already logged in, and pick the specific device when the OS dialog pops up - browsers love to default back to the passkey you already have. 

     

    Hope that gets your second one enrolled!

0/9000

Hey all, 

We are running into issues accessing the mobile app since MFA has been enforced for privileged users. 

  1. If a user sets up the Built-in Authentication on desktop, they are not able to login to mobile. Our company only allows Windows Hello authentication on desktop, and users are unable to "Verify Identity" in iOS when this is added on desktop. The screen is frozen on this even when using "Login for Admin."
  2. We have gone into Salesforce Classic on the mobile browser and added a passkey, but it doesn't work in the app. 
  3. If we delete the Built-in Authenticator on desktop and add a passkey for mobile, it then requires users to have their phones to login on desktop. 

None of these scenarios are ideal, and I'm wondering if anyone has been able to use Window Hello to authenticate desktop and then directly login on mobile with the their Face ID, Touch ID, or passcode? We have found hacky ways to get people logged in with generating a temporary code then having them setup a passkey etc, but it seems like the app should automatically guide users to setup a mobile passkey even when there's an authenticator for desktop? Is this a bug with MFA and mobile because it doesn't seem like this should be expected behavior? 

 

#Multi-Factor-Authentication  #Salesforce1 Mobile App  #Salesforce_Mobile_App

2 risposte
  1. 7 ago, 15:40

    @Tushar Jadav

    none of those links provide the answer if you have read it. People have authenticity to read, analyze and guide. Either you haven't read the question or you are just spamming, please stop.  

     

    @Whitney Pierce Takaba We couldn't find a solution to this problem as well, removing built-in authenticator and enabling Salesforce MFA is the only way currently, which also have it's own bug of forwarding to Salesforce MFA after a weak AMR signal of SSO. If someone has a proper solution, we'll be happy to hear. 

0/9000

Been on hold for hours for support - Still holding, day 5+, tried to use the agent but it cut me off, cases can't be created.  In the meantime, anyone know how to resolve this as I wait......to create a case, or talk to someone.  

 

 I am the sole System Administrator for our Salesforce organization and have become locked out of my account after accidentally deleting the only registered Windows Hello passkey during testing. While my username and password are still valid, Salesforce requires MFA and no longer recognizes any authentication method, leaving me unable to access the organization or reset my own MFA settings. I have already attempted all available recovery options, including "Having Trouble?", checking Chrome and Windows for saved passkeys, and trying multiple devices and browsers, without success. As there are no other administrators in the organization, I am requesting assistance resetting my MFA registration, removing the deleted passkey, issuing a temporary verification code, or otherwise allowing me to register a new authentication method after verifying my identity and ownership of the organization.  

 

#Multi-Factor-Authentication

1 risposta
  1. 4 ago, 15:35

    After holding for 30 minutes again today, just got cut off.  Please call back.  Seriously what is wrong with Salesforce support nowadays. 

0/9000