Resolving Salesforce Authenticator login issues
Last updated: July 27, 2026
Overview
Salesforce requires users to log in with an MFA-compatible app such as Salesforce Authenticator or Microsoft Authenticator. If a user can't access their MFA account, including after uninstalling and reinstalling an authenticator app, it's usually because the old registration remains in their Salesforce user record, preventing the new app from connecting. An admin can resolve the issue using one of the options below.
Generate a temporary verification code
Use this option when a user doesn't have access to their MFA device and needs immediate access. The code expires in 24 hours and isn't a long-term solution.
Go to Setup.
In Global Search, search and select the Users.
Click on the affected user's name.
Scroll to the Temporary Verification Code field and click Generate.
Disconnect the current Authenticator app
Use this option when a user has a new phone, has reinstalled their authenticator app, or is getting consistent errors when logging in. When an authenticator app is reinstalled, the old registration remains in the user's Salesforce record and prevents the new app from connecting. Disconnecting it clears the registration so the user can set up the app again.
Note: Due to security requirements, this can only be completed by a Salesforce administrator.
Go to Setup.
In Global Search, search and select Users.
Click the affected user's name.
Scroll to the App Registration: Salesforce Authenticator (or One-Time Password Authenticator) section and click Disconnect.
Have the user log out and log back in. They'll be prompted to register a new device or authenticator app.
Set up the new Authenticator
After your administrator completes the disconnection, you'll be able to set up the authenticator app again. The next time you log in, Salesforce will automatically prompt you to configure the authenticator app with your account.