Issue
I want to know more about Heroku MFA and MFA Requirement for Salesforce and Heroku customers starting February 1, 2022.
Resolution
Heroku Multi-Factor Authentication FAQ
Customer trust is our highest priority at Salesforce and Heroku. The global threat landscape is constantly evolving, and the types of attacks that can cripple a business and exploit consumers are on the rise. It's more important than ever to implement stronger security measures. That is why we're requiring all customers to enable MFA. MFA is one of the easiest, most effective tools for enhancing login security, and safeguarding your business and data against security threats.
Note
We update this FAQ frequently to address common questions and share additional MFA requirement details. This article was last updated on: January 10, 2023.
Frequently Asked Questions
MFA Essentials
What is MFA and how does it work?
What's the difference between MFA and 2FA?
Requirement to Enable MFA
Is Heroku requiring customers to enable MFA?
Why are Heroku and Salesforce requiring MFA?
When does the MFA requirement go into effect?
Which user, login, and environment types require MFA?
Is MFA required for single sign-on (SSO)?
How will Heroku know if we've enabled MFA for our SSO IdP?
What happens if we can't meet the MFA requirement deadline?
Verification Methods for MFA
Which verification methods satisfy the MFA requirement?
Can users register multiple verification methods?
What is Salesforce Authenticator?
What are third-party TOTP authenticator apps?
What are built-in authenticators?
Can I use desktop or browser-based TOTP authenticators?
Can I use TOTP codes from a password manager?
MFA User Experience
How often do I need to provide a verification method when logging in to Heroku?
What options are available to reduce the additional friction introduced by MFA?
What is the advantage of registering multiple verification methods?
How can users recover access if they forget or lose their verification method?
Learn More
Where can I go if I have questions about MFA for other Salesforce products?