24Flow Customer Documentation

Passwordless Login

Why Passwordless Login

Usernames and passwords can be vulnerable to phishing, password reuse, and credential theft.

Passwordless login allows users to sign in to 24Flow without entering their Salesforce password. Instead, the user verifies their identity with a physical security key.

Salesforce refers to WebAuthn-based security keys and built-in authenticators as Passkeys. These methods provide phishing-resistant authentication and can also be used for faster passwordless login.

How Passwordless Login Works

With passwordless login, the user signs in using:

  1. A remembered Salesforce username.

  2. A physical security key.

  3. The PIN of the security key, when requested.

  4. A physical touch on the security key.

The Salesforce password is not automatically filled in. The passkey stored on the security key replaces the password during login.

Purchase a Security Key

Before configuring passwordless login, purchase a security key that supports FIDO2/WebAuthn.

A commonly used option is a Yubico Security Key.

Enable Passwordless Login in Salesforce

The following configuration must be completed by a Salesforce administrator.

Open Identity Verification

  1. Log in to Salesforce with an administrator account.

  2. Click the gear icon in the upper-right corner.

  3. Select Setup.

  4. In the Quick Find box, search for Identity Verification.

  5. Open Identity Verification.

Allow Physical Security Keys

Under Verification Methods, confirm that the following option is enabled:

Let users verify their identity with a physical security key (passkey) such as U2F or WebAuthn

This setting allows users to register and use a physical FIDO2/WebAuthn security key.

In some Salesforce organizations, this option is enabled by default and cannot be changed.

Enable Passwordless Login

On the same Identity Verification page:

  1. Scroll to the General section.

  2. Enable Allow passwordless login with passkeys.

  3. Click Save.

This setting allows a registered passkey to replace the Salesforce password during login.

Check Session Settings

  1. In Setup, search for Session Settings.

  2. Open Session Settings.

  3. Scroll to Session Security Levels.

  4. Confirm that the following options are available:

    • Passwordless Login.

    • Passwordless Login via Passkeys.

    • Multi-Factor Authentication.

No changes are normally required in this section. This check confirms that passwordless login through passkeys is available in the Salesforce organization.

Check the Authentication Configuration

On the same page, scroll to Authentication Configuration.

A standard configuration can contain the following values:

Setting

Value

Login Page Type

Standard

Authentication Service

Login Form

For a standard Salesforce login, no additional changes are normally required in this section.

Register the Security Key

Each user must register their own physical security key in their personal Salesforce settings.

Open Personal Settings

  1. Log in to Salesforce as the user who will use the security key.

  2. Click the user profile icon in the upper-right corner.

  3. Click Settings.

  4. In the Quick Find box, search for Passkeys.

  5. Open Passkeys.

Add a Passkey

The Passkeys page can contain two sections:

  • Passkeys

  • Security Keys

To configure passwordless login:

  1. Go to the Passkeys section.

  2. Click Add Passkey.

Select the Physical Security Key

After clicking Add Passkey, the browser or operating system opens a passkey selection window.

  1. Select an option such as:

    • Security key.

    • USB security key.

    • External security key.

    • Use another device, followed by Security key.

  2. Insert the security key into the USB port.

Set or Enter the Security Key PIN

The user may be asked to create or enter a PIN for the security key.

This PIN:

  • Belongs to the physical security key.

  • Is not the Salesforce password.

  • Is not the computer password.

  • Can be requested during future sign-ins.

Choose a PIN that the user can remember but that is not easy to guess.

Confirm the Registration

When the security key starts blinking:

  1. Touch the button or contact area on the security key.

  2. Wait until Salesforce confirms the registration.

The registered key will now appear in the Passkeys section.

Where possible, give the passkey a clear name, for example:

Salesforce USB-C Security Key

or:

Shopfloor PC 01 - USB-A Key

Complete the First Login

Before passwordless login can be used, Salesforce must remember the user’s username in the browser.

Sign In with “Remember me”

  1. Open the Salesforce My Domain login URL.

https://companyname.my.salesforce.com
  1. Enter the Salesforce username.

  2. Enter the Salesforce password.

  3. Enable Remember me.

  4. Click Log In.

  5. Complete the MFA verification when requested.

This normal login only needs to be completed once for that browser and computer.

Why “Remember me” Is Required

Salesforce must know which user is signing in before it can find the registered passkey.

By enabling Remember me, Salesforce stores the username in the browser.

During the next login, Salesforce can identify:

  • The stored username.

  • The passkey registered for that user.

  • That passwordless login is enabled.

Note: This setting is browser- and device-specific. The user may need to repeat this step when using another computer, another browser, an incognito window, or after browser cookies have been removed.

Sign In Without a Password

After the security key has been registered and Remember me has been enabled, the normal login process is as follows.

Passwordless Login Process

  1. Open the Salesforce My Domain URL.

https://companyname.my.salesforce.com
  1. Select the remembered Salesforce username.

  2. Insert the physical security key.

  3. Enter the security key PIN when requested.

  4. Touch the security key when it starts blinking.

  5. Salesforce opens without requiring the Salesforce password.

Use the Security Key on Another Computer

The same physical security key can be used on multiple computers.

The passkey does not normally need to be registered again in Salesforce.

However, on every new computer or browser, the user must first:

  1. Sign in once with the Salesforce username and password.

  2. Enable Remember me.

  3. Complete the login.

  4. Test passwordless login again.

Register a Backup Security Key

For administrators and critical users, we recommend registering a second security key.

  1. Open Settings.

  2. Go to Passkeys.

  3. Click Add Passkey.

  4. Register the backup key.

  5. Give the backup key a clear name.

Example:

Backup Security Key

Store the backup security key in a secure location.

Lost or Defective Security Key

When a security key is lost, stolen, or no longer works:

  1. Contact the Salesforce administrator.

  2. Sign in with a backup authentication method or backup security key.

  3. Go to Settings > Passkeys.

  4. Locate the lost or defective key.

  5. Click Delete Passkey.

  6. Register a replacement security key.