Salesforce is preparing for an important change. Beginning February 1, 2022, customers will be required to use multi-factor authentication (MFA) when accessing Salesforce products.
I recently joined Salesforce colleagues and Forrester for a webinar discussing the Total Economic Impact of multi-factor authentication, including Forrester's research into the financial case for MFA and some of what we're learning as we help Salesforce customers prepare for the change.
The security argument for MFA is compelling. Passwords are increasingly inadequate protection against phishing, credential stuffing, and account takeover. But there's another side of the conversation that's just as important.
Implementing MFA isn't simply a security project. It's an adoption project.
The Same Technology, Very Different Users
Salesforce is used in an incredible variety of working environments.
“We have customers that use Salesforce in every way imaginable. We have customers with large call centers. We have people using Salesforce from mobile devices, on factory floors, in retail environments, and just about anywhere you can imagine somebody with a laptop or with a mobile device.”
That's important when we think about a change like MFA. From a technology perspective, the change can seem relatively straightforward: enable another authentication factor and require users to use it.
But the experience can be very different depending on how and where someone works. A salesperson working from a laptop at home has a different workflow than someone in a call center. Someone on a factory floor has different constraints than someone working in an office.
The security control may be standardized, but the human experience isn't.
That's why we've been working closely with customers to understand not only how they implement MFA technically, but how the change fits into the way their employees actually work.
The Security Perimeter Is Changing
The need for stronger authentication is also connected to a much larger change in how we work.
“We are living a new normal. We have more people that are working remote than ever before. We're working in hybrid environments where sometimes you're at the office, but sometimes you're in a coffee shop. Sometimes you are working from home.”
For a long time, companies could build significant portions of their security strategy around physical location. Employees were in an office, on a corporate network, behind a firewall. That's increasingly difficult in a work-from-anywhere environment.
“Many companies over a long period of time built up security based around physical location, physical security. And in order to enable a more remote work environment, MFA is a really important part of that.”
Forrester's Andras Cser described this particularly well during our discussion: identity is becoming the new perimeter. When people can access important business systems from almost anywhere, organizations need greater confidence that the person accessing those systems really is who they claim to be. A password alone increasingly isn't enough.
Security Has a Business Case
One of the things I found particularly interesting about the Forrester study was its attempt to quantify something organizations often discuss only in terms of risk.
Forrester created a composite global organization with $1 billion in annual revenue, 5,000 employees, and approximately half of those employees accessing Salesforce daily.
For that organization, Forrester calculated that implementing MFA from Salesforce could produce a 164% return on investment over three years, with approximately $777,000 in total benefits and a net present value of $483,000.
Much of that value came from reducing the financial risk associated with security breaches. There were also savings associated with Salesforce providing MFA functionality without an additional licensing cost.
That's an important way to think about security investments. Security is often viewed primarily as a cost or a constraint. But stronger security can also enable organizations to operate differently.
A company that has greater confidence in user identity can be more comfortable allowing employees to access sensitive information from different devices and locations.
In that sense, security isn't simply protecting the way we already work. It can enable new ways of working.
Yes, Security Can Add Friction
It's also important to acknowledge the tradeoff. MFA adds a step to authentication.
“If you're only thinking about the login process, the login process is slightly more complex, more cumbersome.”
That's true. But the right comparison isn't between a login with MFA and a login without MFA. It's between the small amount of additional friction and everything that stronger authentication makes possible.
“How much of your day do you really spend logging in? It's probably the thing you do in the morning, maybe after you come back from lunch.”
Good security design isn't necessarily about eliminating every point of friction. It's about making sure the friction we're introducing is proportional to the protection and freedom it provides.
And that brings us to perhaps the most important part of an MFA implementation.
Explain Why
During the webinar, we spent quite a bit of time talking about change management. Salesforce has developed rollout materials that administrators and business leaders can use when introducing MFA to their organizations. That's intentional. Because even when the technology works perfectly, we're still asking people to change their behavior.
As I said:
“Anytime you roll out a change to end users, it's really important to think about what that means to their day-to-day, their work environment, and how to make sure they understand why.”
People are much more likely to accept a change when they understand the reason behind it.
We're not asking someone to take an additional authentication step because we want to make logging in more complicated. We're doing it because passwords are stolen. Phishing attacks happen. Credentials get reused across services. And a second authentication factor can dramatically reduce the usefulness of a stolen password.
Adoption Is Part of Implementation
There's a broader lesson here that extends beyond MFA. When organizations implement technology, it's tempting to think about implementation primarily in technical terms.
- Is it configured correctly?
- Does it work?
- Has it been deployed?
Those are necessary questions, but they're not sufficient. You also have to ask:
- How does this affect someone's day-to-day work?
- Where does it introduce friction?
- Have we given people the tools they need to succeed?
- And, most importantly, do they understand why we're asking them to change?
Technology can be implemented in a day, but behavior rarely changes that quickly.
And as organizations prepare for Salesforce's MFA requirement, that's worth keeping in mind: don't just plan the technology rollout. Plan the human rollout, too.