Salesforce's Mandatory Passkey Rollout Sparks Admin Backlash Over Login Disruptions and Surprise Enforcement

In some cases, users simply found that the "Create Passkey" option failed to work as expected.

Salesforce's Mandatory Passkey Rollout Sparks Admin Backlash Over Login Disruptions and Surprise Enforcement

Salesforce's move to make passkeys a core part of its authentication strategy is drawing criticism from IT administrators and Salesforce professionals, not because they oppose passwordless security, but because of how the rollout has unfolded.

Over the past few weeks, administrators have taken to Reddit, LinkedIn, and community forums to report unexpected passkey prompts, login failures, and increased support requests after Salesforce began enforcing passkey registration for eligible users.

While passkeys are widely regarded as a more secure alternative to passwords, many users The Left Shift has spoken to argue the transition has been abrupt, creating confusion for employees and additional work for IT teams.

The rollout is part of Salesforce's broader effort to strengthen multi-factor authentication (MFA) using phishing-resistant authentication methods.

The company has maintained that passkeys improve both security and user experience, allowing employees to sign in using biometrics, device PINs, or security keys instead of traditional passwords.

Unexpected Prompts and Login Issues Frustrate IT Teams

The most common complaint centres on users suddenly being prompted to create a passkey during login, often without prior notice. Administrators say the unexpected enrollment requests have generated a surge in help desk tickets as employees struggle to understand why their normal login process has changed.

Several Salesforce administrators described situations where users were unable to complete passkey registration altogether. Some reported QR code pairing failures, while others encountered problems detecting devices or syncing passkeys stored in password managers.

In some cases, users simply found that the "Create Passkey" option failed to work as expected. Organisations relying heavily on single sign-on (SSO) have also reported confusion.

Although users authenticate through external identity providers, some administrators say employees were still prompted to register passkeys within Salesforce. The Software-as-a-Service (SaaS) giant has acknowledged a known issue affecting certain SSO scenarios and has published guidance for impacted organisations.

Another pain point involves businesses that still rely on shared Salesforce accounts—an approach discouraged by security experts but still common in some operational environments.

Since passkeys are designed to be tied to individual users and devices, these organisations have found their existing workflows disrupted, forcing them to explore alternatives such as shared password managers or hardware security keys.

Several administrators also said Salesforce Support offered temporary extensions or workarounds, including time-limited passcode options, to help organisations complete the migration without disrupting business operations.