Version Affected: All
Overview
Since Salesforce began requiring device activation for Single Sign-On (SSO) logins on February 3, 2026, users who already completed multi-factor authentication (MFA) through SecureAuth Identity Platform (SAIDP) may be prompted for MFA a second time by Salesforce. Setting an appropriate AuthnContext Class value on the realm tells Salesforce that MFA has already been satisfied, avoiding the second prompt.
Set the AuthnContext Class on the Realm
- On the realm, go to the Post Authentication tab.
- Under the SAML Assertion / WS Federation section, click the AuthnContext Class dropdown.
- Choose one of the following values: MobileTwoFactorContract, PGP, Smartcard, or TimeSyncToken.
- Save the realm and test a login to confirm Salesforce no longer prompts for a second MFA step.
See Salesforce's Changes to Device Activation for Single Sign-On (SSO) Logins for the full detail on this requirement.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.