Salesforce Shared Admin Account Under 2026 MFA
By Kalpesh Mahida · Updated August 29, 2026
If your team signs in to one Salesforce System Administrator login, the 2026 security change hit you harder than anyone. Admin profiles are exactly what Salesforce now forces onto phishing-resistant multi-factor authentication, and a phishing-resistant factor is bound to a device. That is the whole problem with a shared admin account. This guide walks the real options, with the honest tradeoff of each, and no pretending there is only one answer.
Why the admin account is the hardest case
A regular user who trips a permission can sometimes avoid the strictest requirements. An admin cannot. The System Administrator profile, and high-trust permissions like Modify All Data, View All Data, Customize Application, and Author Apex, are precisely the accounts Salesforce wants behind a phishing-resistant factor. So the one login a small team is most likely to share, the admin, is the one the mandate locks down first.
What Salesforce now requires for admins
A one-time code from an authenticator app or an SMS message no longer clears the bar for privileged users. The accepted factors are:
- Passkeys
- Built-in device authenticators such as Touch ID, Face ID, or Windows Hello
- Hardware security keys such as a YubiKey
All three tie the login to something physical. Great for one person protecting one account. A problem the moment a team needs the same admin login.
Your options for a shared admin account
The right choice depends on whether the admin account is genuinely a shared service account, how often people need it, and how much you care about an individual audit trail.
Option 1: Give each admin their own seat and passkey
The clean answer when it fits. If each person is really a separate admin who should have their own access and audit trail, buy the seat and let each enroll their own passkey. Nothing to work around. Painful when you are a small shop that shared one admin login precisely because you did not need or could not justify several full admin seats.
Option 2: Temporary Verification Code
An admin can generate a Temporary Verification Code for a user from Advanced User Details. It expires in 1 to 24 hours. Good for rare, short-lived access. Painful for a team that needs the admin login regularly, because someone has to mint a fresh code every time, and a typed code is a weaker factor than the passkey it stands in for.
Option 3: A shared password manager that stores the passkey
Salesforce guidance for shared accounts is to keep the credential in a password manager that provides the verification method. In 2026 the major managers can store and share passkeys. Good if your team already runs a full manager. Painful when you only need to share one admin login and now have to roll out and pay for a whole suite to do it.
Option 4: A single-purpose shared-login tool
This is the option I build, so read it as the vendor view told straight. Coauth is a free Chrome extension that does one thing: let a team share one login, passkey or password, without buying everyone a seat. Honest limit: it is a young single-purpose tool, not an enterprise password platform. If you need company-wide management, org policy, and SSO, a full suite fits better.
What Salesforce itself says about shared logins
Salesforce does not forbid a shared service account. Its own guidance points to storing the shared credential in a password manager that supplies the verification method. That is the key point people miss: using a manager to hold and share the passkey for a genuine service account is a sanctioned pattern, not a bypass of MFA. The factor Salesforce checks is unchanged. What changes is that the passkey lives in an encrypted vault the team can use, instead of on one person device.
How to share a Salesforce admin passkey with Coauth
- Install Coauth from the Chrome Web Store and secure your vault with your device passkey. No master password.
- Register a new passkey for the shared admin account through Coauth, or save the login.
- Create a team and share the admin login into it.
- Invite the other admins with a code. The shared login appears in their vault, decrypted only on their device.
- When someone leaves, remove them. The team key rotates, so their old copy can no longer decrypt the login.
Each admin signs in with one click on their own machine. No code to reissue, no extra seat to buy, and access you can pull the moment you need to.
Security guardrails before sharing an admin login
- Share only a true service account. Anything that needs a personal audit trail should be an individual named user.
- Choose a tool that is zero-knowledge, so a breach of the vendor exposes only ciphertext.
- Confirm that removing a member actually rotates the key, not just hides the entry.
- Keep a recovery path and confirm the vendor runs backups.
Frequently asked questions
Can a shared Salesforce admin account use a passkey?
Yes, if the passkey lives in a manager that can share it. A passkey bound to one person device cannot be handed around, but a software passkey stored in a shared vault or a tool like Coauth can be used by every member of the team from their own browser.
Does sharing the admin passkey break the MFA rule?
No. The factor is still a phishing-resistant passkey. You are sharing it through an encrypted vault instead of each person owning a separate one. Salesforce guidance for shared accounts points to exactly this pattern.
Should we just buy each admin a seat?
If each person needs their own accountability or you are under compliance rules that require named users, yes. Sharing a privileged login always trades some auditability for convenience. Make that trade on purpose, only for genuine service accounts.
What happens when an admin leaves the team?
Remove them and the shared key rotates. Their old copy can no longer decrypt the login, so access ends immediately. For a password, also change the credential itself, as with any manager.
Share one login without buying five seats
Coauth is live on the Chrome Web Store and free to start. Zero-knowledge, one-click sign-in, revoke anyone in a click.
Add Coauth to Chrome →