Q&A: Salesforce MFA Updates (June 2026)
Table of Contents
On June 10th, 2026 the HomeKeeper Support Team hosted a Q&A session for all Salesforce Admins and Users to review and answer questions about Salesforce's upcoming MFA policy changes. These changes may effect any existing HomeKeeper user's (created prior to these changes) ability to log into Salesforce and Access HomeKeeper.
Watch the Recording
The Changes
All users must set up a compliant Multi-Factor Authentication (MFA) method
Key dates:
- June 10 – Q&A session
- June 22 – Sandbox enforcement begins (use this to test your setup)
- July 1 – Phishing-resistant MFA enforced in production
- July 20 – Standard MFA enforced in production
System Administrator and HomeKeeper Administrator Users:
You must now use a phishing-resistant MFA specifically — options include Touch ID, Face ID, Windows Hello, or physical security keys (YubiKey, Titan Key), or the HomeKeeper Administrator Profile must be modified or cloned to remove the phishing-resistant requirement.
- The Salesforce Authenticator App and SMS/text and email verification codes will no longer be accepted for HomeKeeper Administrators (with out of the box permissions) or System Admins.
Your Options as an Admin:
- Set up all Salesforce and HomeKeeper Administrator users with phishing-resistant MFA
- *Remove System Administrator permissions from the HomeKeeper Administrator User (Recommended - instructions below)
- *Clone the HomeKeeper Administrator profile, rename it HomeKeeper User, and remove System Administrator permissions (Recommended - instructions below)
- Reconfigure HomeKeeper Administrator users to the Standard User profile with the HomeKeeper User – Unmanaged permission set (if you do not have this permission set, reach out to HomeKeeper Support to receive it)
- If your org already uses phishing-resistant MFA, no action is needed
Edit or Clone HomeKeeper Administrator Profile to Remove System Administrator Permissions
Follow the instructions below to either alter the existing HomeKeeper Admistrator permissions that trigger the phishing resistant MFA requirement, or clone it to create a new custom profile that can be assigned to users.
First 1) go to Setup, 2) search for Profiles, 3) find the HomeKeeper Administrator profile

NOTE: If you'd like to create a new profile to assign to the users, click “clone” to create a copy of the existing HomeKeeper Administrator Profile. Rename it “HomeKeeper User” then follow the next steps:

Then, click on System Permissions and click edit

Scroll or use CTRL-F (or Apple F for Mac users) to find the following permissions and uncheck the corresponding boxes:
- Modify All Data
- View All Data
- Author Apex
- Customize Application

Save your changes.
NOTE: If you created a new custom profile, it will need to now be assigned to all users who were previously assigned to HomeKeeper Administrator.
1) Click on Assigned Users then 2) click Add Multiple Users to assign multiple users at once to the new Profile.


If locked out: HomeKeeper cannot help — you must contact Salesforce Support directly (help.salesforce.com or 1-800-664-9073). Save your Org ID now to make this easier.
Resources
- Salesforce Help: Prepare for Phishing-Resistent MFA Enforcement
- Salesforce Help: Prepare for MFA Enforcement for All Users
- Free Like a Puppy: The MFA Scramble (How to Setup)