SupportLogin
Talk to us
How Does Salesforce Multi‑Factor Authentication Affect Integrations?

How Does Salesforce Multi‑Factor Authentication Affect Integrations?

March 12, 2025 · Andreea Arseni · Salesforce integration

Salesforce Multi‑Factor Authentication (MFA) affects integrations by requiring an additional verification step for any interactive login.

This means that integrations relying on standard user credentials—such as username and password—can fail once MFA is enforced. To prevent disruptions, the best practice is to use a dedicated API-only integration user, which is exempt from MFA and ensures uninterrupted system-to-system access.

Salesforce now requires Multi-factor Authentication (MFA) which is mandatory for all direct UI logins in order to prevent security breaches that can happen due to credential theft or weak passwords.

However, the enforcement varies based on how users access Salesforce, particularly for automated integrations.

In this article we will explain what is Multi-factor authentication, who is impacted by and exempt from the Salesforce MFA and how it affects integrations and what actions to take in order to avoid any disruptions in regards to your integration.

 

 

Table of concepts

 

 

WHAT IS Salesforce MULTI-Factor Authentication (MFA)?

Salesforce Multi-Factor Authentication (MFA) adds an extra layer of security to your account login process.

Instead of relying solely on a username and password, MFA requires an additional verification step—this could be a code from a mobile app, a hardware security key, or a one-time passcode delivered via SMS or email. By combining something you know (your password) with something you have (the additional factor), Salesforce makes it much harder for unauthorized users to gain access to your account, even if your password is compromised.

 

Methods of Salesforce Multi-Factor Authentication (MFA)

Salesforce has implemented Multi-Factor Authentication (MFA) as an extra layer of security to protect user accounts from unauthorized access. Instead of relying solely on a username and password, MFA requires users to verify their identity using a second authentication factor. Options include:

Who is impacted by Salesforce MFA?

MFA applies to any user logging into Salesforce through the standard login page or any application that requires an interactive login. The following user types are affected:

1. Standard Salesforce Users (Admins and Regular Users)
2. Users Accessing Salesforce via SSO (Without MFA at the IdP Level)

Who is exempt from the Salesforce MFA?

Certain users and authentication methods do not require MFA enforcement, including:

1. API-Only and Integration Users 2. Users Logging in via SSO (with MFA at the IdP Level) 3. Guest and Public Users

How Does MFA Impact Salesforce Integrations?

If an integration relies on a regular user’s credentials for authentication (e.g., logging in with a username and password), it will fail once MFA enforcement is enabled. This is because:

For example, if an iPaaS connects to Salesforce using a regular user’s login credentials, it will break once MFA is enforced.

 

What Are the Best Practices for Avoiding MFA-Related Integration Failures?

To prevent disruptions, integrations should use authentication methods that bypass the need for interactive MFA:

Use a Dedicated API-Only Integration User

To make the switch from using a regular user for any integration to a dedicated API-only integration user, follow these steps:

  1. Follow the steps in this article on how to set up your salesforce integration user.
  2. After you have configured your integration user correctly, you would need to re-authorize your current Salesforce connection within MyRapidi via the new integration user.

And that’s it! 

Using a dedicated API-only integration user is essential for security, stability, and compliance. Also, an API-only integration user is specifically configured for system-to-system communication, ensuring uninterrupted access at all times.


If you need assistance please contact our support team.

Ready to Upgrade Your Systems?

 

 

How does Salesforce MFA impact Integrations that use standard user credentials?

Integrations using a regular Salesforce user’s login can fail when MFA is enforced because the second authentication factor cannot be provided automatically. The recommended solution is to use a dedicated API-only integration user, which is exempt from MFA.

Who is exempt from Salesforce MFA when Integrating with external systems?

Users authenticating via API-only accounts, OAuth flows, or security tokens do not require MFA. Additionally, users logging in through SSO with MFA enforced at the Identity Provider level are also exempt, ensuring integrations continue to function without interruptions.

What are the best practices to avoid MFA-related Integration failures?

Use a dedicated API-only integration user with only the necessary permissions, re-authorize your current Salesforce connections via this account, and follow proper setup steps. This ensures security and prevents disruptions caused by MFA enforcement.

 

 

Updated January 2026

 

Find out if this fits your setup

Tell us which systems you run and we will tell you plainly whether Rapidi is the right tool.

Free, 17 pages

Get the Salesforce and Business Central solution sheet

How the integration is built, what the RapidiConnector secures, the pre-configured templates, and the eight transfers most customers start with.