Salesforce Device Activation Prompts Despite Okta Sending Required AMR Claims
Last Updated:
Overview
With Salesforce's mandatory Multi-Factor Authentication (MFA) requirements, end users should not receive a device activation prompt if Okta sends the necessary Authentication Method Reference (AMR) claims via the Security Assertion Markup Language (SAML) payload. However, users may still receive this prompt if a specific Salesforce setting is enabled. Disabling the Use Salesforce MFA for this SSO Provider setting resolves the issue.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Salesforce Device Activation
- Authentication Method Reference (AMR) Claims
- Security Assertion Markup Language (SAML)
Cause
This issue occurs when the Use Salesforce MFA for this SSO Provider setting is enabled on the Salesforce side, which causes Salesforce to ignore the AMR claims sent from Okta.
Solution
How is the Salesforce device activation prompt resolved?
Disable the Salesforce MFA setting for the SSO provider in the Salesforce Admin Console to resolve the device activation prompt.
- Sign in to the Salesforce Admin Console.
- Go to Identity Providers on the left-hand pane.
- Select Single Sign-On Settings.
- Find the Okta Identity Provider (IdP) configuration and select Edit under Action.
- Clear the Use Salesforce MFA for this SSO Provider checkbox.
- Select Save.
- Retry the authentication flow.
