top of page
  • Black Instagram Icon
Search

Navigating the Salesforce Passkey Rollout: Overcoming the Shared Account Challenge with 1Password



As Salesforce aggressively pushes toward mandatory multi-factor authentication (MFA) and seamless passwordless identity management, Passkeys (FIDO2 / WebAuthn) have emerged as the standard for securing cloud enterprise platforms. Passkeys virtually eliminate phishing risks by anchoring cryptographic key pairs to biometric hardware or secure vaults.

However, the shift to passkeys introduces a major operational hurdle for organizations relying on shared user accounts. While single-user authentication works cleanly out of the box, standard browser passkey implementations break workflows where multiple team members rely on a single login.

1. Common Scenarios Impacted by the Passkey Mandate

Despite Salesforce best practices favoring individual user licenses, budget constraints or legacy system architectures mean many organizations deploy shared logins for specific workflows:

  • Data Entry Teams in the Same Location: Teams operating in branch offices, shift-based operations, or warehouses where multiple employees log into a shared account to record high-volume routine data or daily receipts.

  • Report Viewers & Dashboard Displays: Departments utilizing a dedicated read-only account to power shared TV displays, wallboards, or regional reporting consoles.

  • Third-Party Vendors & Support Teams: Shared contractor accounts assigned to outsourced teams managing specialized routine processing.

2. The Core Technical Friction: Default Browser-Bound Vaults

When an end user registers a passkey on Salesforce by default, the web browser or OS saves the private key into a personal online vault—such as Google Password Manager, Apple iCloud Keychain, or Windows Hello.

⚠️ The Operational Trap: Once registered, the passkey is locked inside that single user's personal Google/Apple account or physical device. If Shift Worker A registers the passkey on their browser, Shift Worker B coming in for the next shift cannot log into the shared Salesforce account without physical access to Worker A’s personal device or biometrics.

3. The Workaround: Sharing Passkeys with 1Password

To preserve shared account workflows without compromising security or violating Salesforce's authentication requirements, companies can leverage 1Password for Business / Teams.

Unlike native browser password managers, 1Password supports storing, managing, and syncing FIDO2 / WebAuthn passkeys inside Shared Vaults, allowing authorized team members to authenticate seamlessly across workstations.

4. Step-by-Step Implementation Guide

Step 1: Create a Dedicated Shared Vault in 1Password

  1. Log into your 1Password administrative console.

  2. Create a new vault dedicated to the shared operational function (e.g., Salesforce Shared Data Entry).

  3. Assign explicit read/write access to the specific team group (e.g., "Shift A Operations").

Step 2: Configure 1Password Browser Extension

  1. Ensure all team members have the official 1Password extension installed on their work browsers.

  2. Under 1Password Extension Settings > Autofill, enable "Offer to save and sign in with passkeys".

  3. Disable native browser password managers (Chrome/Edge settings) to avoid conflicting prompts during authentication.

Step 3: Register the Salesforce Passkey in 1Password

  1. Log into the target shared account on Salesforce.com.

  2. Navigate to User Settings > Advanced User Details > Security Keys (WebAuthn) (or follow the automated prompt upon MFA enforcement).

  3. Click Register / Add Security Key.

  4. When prompted by the browser to create a passkey, 1Password will intercept the request. Select the item in your Salesforce Shared Data Entry vault and save the passkey there.

Step 4: Verify Cross-Team Login Access

  1. Have a second team member open Salesforce on their workstation.

  2. When prompted for authentication, 1Password will automatically display the shared passkey stored in the common vault.

  3. Click approve, and the team member is logged in smoothly without requiring physical access to the original user's device.

5. Security & Governance Considerations

While using a shared passkey vault bridges immediate operational gaps, long-term enterprise governance should keep the following in mind:

  • Role-Based Vault Access Control: Ensure strict RBAC on the 1Password vault so access is revoked immediately when an employee offboards.

  • Master Password & 2FA Enforcement: Enforce strong two-factor authentication across all 1Password user accounts safeguarding the shared vault.

  • Transition Path to Individual Licenses: Long-term, moving toward individual user licensing, permission sets, and detailed Audit Trail logging remains the ideal solution for comprehensive compliance and identity traceability.

 
 
 

Comments


Tentspark Sdn Bhd (1040511-M)

Block B, Unit 8, Level 3A, Icon City, Jalan SS 8/39, Sungai Way Free Trade Industrial Zone, 47300 Petaling Jaya, Selangor

© 2018 by Tentspark Sdn Bhd. Data Protection Policy Privacy Policy

bottom of page