Beyond Phishing Resistance: Proving Who Is Accessing Salesforce


Salesforce is strengthening authentication for privileged users. Token argues that enterprises should go further by verifying the person behind the credential.

Listen to this article

Salesforce administrators hold the keys to an extraordinary amount of sensitive information.

Depending on the organization, that may include customer records, sales projections, financial histories, donor information, support cases, business workflows, connected applications, and the permissions governing who can access all of it.

That makes an administrator’s account far more than another corporate login. It is a high-value identity—and an increasingly attractive target.

Salesforce has responded by strengthening its authentication requirements. Beginning June 26, 2026, the company began enforcing phishing-resistant multifactor authentication for administrators and other privileged users.

The change represents an important step forward. It also raises a question security teams should consider carefully:

What, exactly, does a successful authentication prove?

Why Attack the Platform When You Can Become the Administrator?

Attackers do not always need to discover an exploitable vulnerability in an enterprise application. Sometimes it is easier to persuade the application that the attacker is an authorized user.

Threat actors can steal passwords. One-time codes can be intercepted or relayed. Distracted or exhausted users can accidentally approve push notifications. Help desks can be manipulated, and convincing voice calls can make fraudulent requests sound entirely legitimate.

AI is making many of these attacks easier to personalize and harder to recognize.

The objective is generally the same: acquire enough of a trusted identity to enter through the front door.

Privileged Salesforce accounts are especially valuable because their permissions may allow an intruder to view large collections of data, modify configurations, change access rights, create integrations, or interfere with the workflows on which the business depends.

Salesforce’s decision to require stronger authentication for privileged users therefore reflects a broader reality. Identity has become one of the primary battlegrounds in enterprise security.

What Makes Authentication Phishing-Resistant?

Traditional MFA improves security by requiring something beyond a password. Unfortunately, not every second factor provides the same degree of protection.

A one-time code can still be entered into a convincing counterfeit website. A fraudulent push notification can still be approved. An attacker using an adversary-in-the-middle phishing page may even relay credentials and codes to the legitimate service in real time.

Phishing-resistant authentication works differently.

Technologies based on FIDO2 and WebAuthn use cryptography to bind authentication to the legitimate website or service. If a user encounters a counterfeit Salesforce login page, the authentication process detects that the requesting origin does not match the one for which the credential was registered. It will not provide the response the fraudulent site needs.

That removes an important weakness from the process: the user is no longer solely responsible for recognizing whether a login page is genuine.

Salesforce now requires this stronger protection for privileged users, including system administrators and users holding certain elevated permissions. The company’s implementation guidance encourages organizations to identify affected accounts, review whether all elevated privileges remain necessary, test authentication flows, and prepare backup methods before enforcement affects production access.

Those are sensible precautions. Authentication changes can create operational problems of their own if organizations fail to plan for lost devices, unavailable biometrics, or administrator lockouts.

But phishing resistance addresses only part of the identity question.

Possession Is Not Necessarily Identity

A conventional hardware security key can provide very strong protection against phishing. It demonstrates that an enrolled authenticator is present and responding to a challenge from the legitimate service.

What it may not establish by itself is which person possesses the device.

That distinction will not be equally important for every user or every application. For privileged accounts, however, it deserves attention.

Token is approaching the problem by combining phishing-resistant authentication with fingerprint verification and dedicated hardware. According to the company’s recent announcement, each authentication event requires the registered Token device, verification of the enrolled user’s fingerprint, and a cryptographic challenge tied to the legitimate service.

TokenCore Wearable places the fingerprint sensor in a ring-style wireless authenticator worn on the user’s finger. TokenCore Portable provides the same general authentication model in a portable wireless device.

The distinction Token is emphasizing is subtle but meaningful. Phishing resistance demonstrates that the authenticator is communicating with the proper service. Hardware binding demonstrates possession of the enrolled device. Fingerprint verification adds evidence that the person assigned to that device is physically present.

In other words, the security progression looks something like this:

First, does the person know the credential?

Second, does the person possess the registered authenticator?

Finally, is there evidence that this is the authorized person—not merely someone holding that person’s device?

Kevin Surace, CEO of Token, describes this as providing “stronger proof of the human behind every Salesforce login.”

That is a compelling objective, particularly for administrators, executives, developers, and others whose accounts can provide broad access to sensitive systems.

Biometrics Require Careful Evaluation

Biometric authentication should not be treated as magic.

A fingerprint is not a secret that can be replaced as easily as a password. Organizations evaluating biometric authenticators should understand where biometric information is stored, whether it ever leaves the device, how enrollment is protected, and what happens when a legitimate fingerprint is rejected.

They should also examine device recovery, reassignment, revocation, loss reporting, and emergency access.

A poorly designed recovery process can still undermine the strongest authenticator. If an attacker can persuade a help desk to bypass the control, the organization has protected the front entrance while leaving a side door open.

This is one reason Salesforce recommends registering backup phishing-resistant methods and establishing an emergency “break glass” procedure. The objective is not merely to deploy stronger authentication. It is to create an identity lifecycle that remains secure during enrollment, everyday use, device loss, employee departure, and account recovery.

Token’s value proposition is strongest when viewed within that larger program.

Shared Access Is Increasingly Difficult to Defend

Token’s announcement also touches on Salesforce partners, consultants, support teams, and nonprofit organizations that may have relied historically on shared access practices.

This is an area where stronger authentication can expose a deeper policy problem.

A password manager can control access to a shared credential, but it does not necessarily establish who ultimately used the account. Similarly, possession of a shared authenticator may demonstrate that someone on the team has the device without establishing which individual initiated a privileged action.

The better answer is not to attach biometric authentication to a broadly shared identity. It is to move away from shared privileged accounts wherever possible.

Each administrator should have an individually assigned identity, only the permissions required for that person’s work, and an authentication method that supports reliable attribution. Token’s hardware-bound biometric approach fits naturally into that model because the authenticator can be assigned to a particular authorized person.

That can strengthen both security and accountability.

Going Beyond the Minimum Requirement

Organizations could treat Salesforce’s new MFA requirement as a compliance exercise: determine which authentication methods qualify, select one, deploy it, and move on.

That would miss the larger opportunity.

The better exercise is to examine what an organization wants a successful login to prove.

For ordinary workforce access, a built-in authenticator or conventional security key may provide the appropriate balance of security, cost, and convenience. For highly privileged access, organizations may decide that possession of an authenticator is not enough. They may want stronger evidence that the assigned human is actually present.

Token is positioning TokenCore Wearable and TokenCore Portable for precisely that use case.

Its combination of FIDO2/WebAuthn authentication, protected hardware, and fingerprint verification provides Salesforce customers with a way to move beyond passwords, codes, and approval prompts. It also offers an answer to the identity-assurance question that remains after phishing resistance has been achieved.

No authentication technology can eliminate every account-takeover scenario. Sessions can be stolen after authentication. Endpoints can be compromised. Permissions can be misconfigured. Enrollment and recovery processes can be manipulated.

Still, the direction is clear.

As attackers become better at imitating trusted communications and manipulating legitimate users, enterprise authentication must rely less on whether someone can provide the expected response and more on whether the system can verify the service, the device, and the human involved.

Salesforce is raising the minimum standard for privileged access.

Token is making the case that organizations should go higher.


Additional Resources

Video Overview

Infographic


Steven Bowcut is the Editor-in-Chief of Brilliance Security Magazine and host of the BSM Podcast. He has spent years covering cybersecurity and physical security, focusing on the technologies, strategies, and leadership insights that matter most to security practitioners and decision-makers. Through the magazine and podcast, Steven brings readers and listeners practical content with industry leaders, innovators, and experts shaping the future of security. Follow and connect with Steve on Instagram and LinkedIn.