Today on the Salesforce Admins Podcast, we talk to Jay Hurst, Senior Vice President of Product Management, and James Ferguson, Senior Director of Product Management, at Salesforce. Join us as we chat about MFA step-up authentication and what it means for Salesforce Admins. You should subscribe for the full episode, but here are a few takeaways from our conversation with Jay Hurst and James Ferguson. Step-up authentication protects sensitive actions Starting next week, Salesforce is requiring all users to use Multi-Factor Authentication (MFA). If you're a privileged user like, for example, an admin, you'll need to use a phishing-resistant MFA. That's why I sat down with Jay Hurst, VP of Product Management, and James Ferguson, Senior Director of Product Management, to talk about why these changes are vital to protect your org's data. The first thing to know is that AI is making it easier than ever to launch targeted phishing attacks at scale. So while the MFA requirements provide a good first layer of protection, we want to make extra sure you are who you say you are before you're allowed to perform certain actions, like downloading a large number of records or running a big report. Phishing-resistant MFA uses a passkey, like a fingerprint or facial recognition biometric, to verify that it's actually you and not just someone with access to your email account. Balancing security with user friction As Jay and James acknowledge, these changes will add some friction to your users' experience. However, with the pace at which these kinds of attacks are evolving, it's more important than ever to get serious about your security posture. "We're trying to introduce a little more friction right now so that people start to think," Jay explains, "and start to build those habits of understanding when they're doing something that potentially could be considered a malicious attack, such as downloading that All Opportunities report." They're also building out compensating controls that should make things easier in the future, allowing you to trust users from a certain IP range, for example. Security is a journey, not a destination The most important thing to realize is that these requirements are about more than just jumping through some extra hoops. Phishing and man-in-the-middle attacks are growing more and more sophisticated, and you need better protections than "Well, that hasn't happened yet." Instead, James and Jay recommend viewing this as an opportunity to partner with other stakeholders in your org to develop a comprehensive security plan. As Jay says, "Security is a journey, not a destination. What is 100% secure today is not as secure tomorrow." The trick is to develop a security-focused mindset throughout your business that will protect you now and in the future. Make sure to listen to my full conversation with Jay and James for more on step-up authentication and how admins can reduce friction for users. And make sure you're subscribed to the Salesforce Admins Podcast so you never miss an episode. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Admins Podcast Episode: What Are Security Essentials for Salesforce Admins? Salesforce Admins Blog Post: Securing Your Org: From Reactive to Proactive Salesforce Help Article: Prepare for the upcoming Step-up Authentication requirements on Report Actions Salesforce Help Article: Prepare for MFA Enforcement for All Employee Users Salesforce Help Article: Prepare for Phishing-Resistant MFA Enforcement for Privileged Users including Admins Salesforce Help Article: Security-Related Product Updates to the Salesforce Platform: User Identity, Data Protection, and Access Controls Admin Trailblazers Group Admin Trailblazers Community Group Social Jay on LinkedIn James on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: This week on the Salesforce Admins Podcast, we're talking with Jay Hurst and James Ferguson from Salesforce Product Management about MFA step-up authentication and what it means for Salesforce admins. As you know, security isn't just a front-door login decision anymore. It's about protecting sensitive actions, understanding risk, and designing systems users can trust. So Jay and James are going to help us unpack phishing-resistant MFA, compensating controls, IP ranges, SSO, and why these changes matter in a world where data, automation and AI are all working together. For us Salesforce admins, this is a chance to think beyond features and really look at how we steward the entire system. So listen in, click that Subscribe button, and of course I would love if you could share it with fellow Salesforce admins or, hey, you know what? Let's make some friends in that security team. So with that, let's get Jay and James on the podcast. So Jay and James, welcome to the podcast. Jay Hurst: Thanks for having us, Mike. James Ferguson: Great to be here. Mike: Absolutely. Jay, let's start off with you. We kind of want to get to know a little bit about you, and James, we'll call on you second, but before we get into our topic today, can you just tell me a little bit about how you got to Salesforce and what you do? Jay Hurst: Sure, yeah. So I have been with Salesforce for almost 22 years now. I started in our customer support department, one of the first 12 phone support reps here at Salesforce. Did that for a couple years and helped found our Tier 3 organization in support. Eventually moved over to our customer-centric engineering department, stayed in there for a while. And then in 2012, had an opportunity to join the product management group for platform, and I moved over and ran a team called Force.com Canvas. And for the last, I guess, 12-ish years now, I've been kind of weaving my way upwards through platform. Currently, I lead our platform services subcloud, so all of the core foundational pieces of platform that you might think of are schema and metadata, APIs, eventing systems, connectivity systems, and also our identity area, which is what brings us here today to talk about MFA. Mike: Yeah. Boy, flashback. You called it the Force.com platform. Jay Hurst: Well, that's what it was called back then. Mike: I know. I know. Jay Hurst: And I can't remember all of the names we've had for it. Mike: Oh, that's okay. I'm sure there's a website that tracks all of them. Jay Hurst: I'm sure there is. Mike: James, fill us in. How'd you get to Salesforce, and what do you do here? James Ferguson: Well, I am, I guess compared to Jay, one of the newer members of the team. I've only been at Salesforce for about 16 and a half years, almost 17 years. Pretty much entirely on the platform product management side, working on various things people know and love like sharing and big objects and event monitoring and those things. And most recently I've taken over responsibility for the identity product team, responsible for all the login and auth and SSO and all of the wonderful things we'll talk about today. Mike: Oh, wow. Okay. So then just to be clear, I'm actually the newest person on this call. I've only been at Salesforce for a little over 12 years now, so I guess I still have my rookie stripes. Jay Hurst: Combined we're almost at 40, or just over 40. Mike: Yeah, combined. We almost get our AARP discount, right? Jay Hurst: Yeah, exactly. Mike: Jay, let's kick off. I know I did a podcast ... and I'll link back to it ... not that long ago with Laura Pelke talking about some of the new things that were coming out, and of course security is always big on admins' mind. She did a wonderful job of explaining step-up authentication to me, which was basically the airport analogy of you have to show your ID to get in and then you have to show your boarding pass to get onto the plane. I thought that really made sense to me, but let's talk about the new authentication that's coming out, if you call it that, and the new step-up concerns that Salesforce admins have. Jay Hurst: Sure. So I think as we move into the continued proliferation of agents and AI across the industry, security is obviously top of mind for a lot of our customers and for Salesforce as well, specifically because we have to help protect our customers. And so when we're thinking of that and how we ensure our customers' data is protected, with step-up authentication, it's really focused around in that same analogy, making sure you're providing your boarding pass at the right times when you're doing things. So just like you need to show your boarding pass when you go through the TSA gate and when you're on the plane and probably to the gate agent after you're on the plane, when you're doing certain things within Salesforce, we want to make sure you are who you actually are and your session hasn't been compromised. So when you're doing certain higher sensitivity-type actions such as I want to download 10,000 records out of my system, maybe run a report, putting that end user through another verification of, "Hey, is this actually you? Prove it with your step-up," so that we have that confidence that we can release the records. And so this kind of helps prevent some of those man-in-the-middle phishing attacks where somebody gets you to log in and then steals your credentials or steals your session in the background. So it's kind of that second or third or fourth level of protection in the runtime. Mike: Wow. James Ferguson: I think that's an important shift that's worth calling out, because it's no longer about just putting a stronger lock on the front door and making sure somebody has better passwords, or even the later stuff, the more recent stuff with verification. But it's when sensitive things happen, we need to do a little extra even once you're inside the airport, if we want to continue that analogy. And so i