Use this link to share with your colleagues:
Using Multi-Factor Authentication (MFA): https://help.patronmanager.com/a/1992972
When logging into your PatronManager account, you'll need to use multi-factor authentication (MFA) to verify your login. This ensures that your data and account is secure! This article shares essential information about MFA and how to set it up for your user.
If you're an admin, you must use a Salesforce-approved phishing-resistant form of MFA. Learn more about those requirements and how to set it up here.
What is MFA?
Multi-Factor Authentication adds another layer of security to your login process by requiring users to enter two or more pieces of evidence — or factors — to prove they’re who they say they are. One factor is something the user knows, such as their username and password. Other factors are verification methods that the user has in their possession, such as an authenticator app on their phone. A familiar example of MFA at work is the two factors needed to withdraw money from an ATM. Your ATM card is something that you have and your PIN is something you know.
By tying user access to multiple, different types of authentication factors, it’s much harder for a bad actor to access your PatronManager account. For example, even if a user’s password is stolen, the odds are very low that an attacker will also be able to guess or hack a code from the user’s authentication app.
What are my options for MFA?
MFA typically uses a special app that you install on your phone or a physical security key that you place into your device. That means you'll need to have your phone or security key with you every time you log in to PatronManager.
Some organizations may use other methods, like a password manager (e.g., Google Password Manager, LastPass, or 1Password) or your device's biometric recognition (e.g., Apple Touch ID or Windows Hello). These other options may require additional setup steps from Salesforce, which we've linked to above.
For users with any of the following admin attributes, Salesforce requires a phishing-resistant MFA method.
- The System Administrator Profile, or
- A Profile or Permission Set that gives permission to do any of the following:
- Modify All Data
- View All Data
- Customize Application
- Author Apex
We've highlighted phishing-resistant MFA methods below.
Even if you choose to use a password manager or physical security key, we recommend setting up an authenticator app on your phone as well as a backup!
In general, we recommend that each user set up 2 different MFA methods.
How to connect an authenticator
1. Go to log into PatronManager
This may be from an invitation to log in for the first time, or it may be after logging in by entering your Username and Password.
3. Connect your primary authentication method
The steps will vary depending on the method you chose.
If you're not sure which authentication method to use, we recommend Google Password Manager or biometric recognition!
To link a biometric recognition method, follow the steps here.
To link a physical security key, follow the steps here.
To link a password manager, follow the steps here.
4. Connect your secondary authentication method
The steps will vary depending on the method you chose.
If you plan to use an app for a secondary authentication method, the app you wish to use on your phone, if you haven't already
For Android, find your app in the Google Play Store; for iOS, find it in the App Store. Download either the Salesforce Authenticator app, or the third-party app your organization has approved. If you're not sure which app to use, talk to your manager.
To link a biometric recognition method, follow the steps here.
To link a physical security key, follow the steps here.
To link a password manager, follow the steps here.
This is not considered a phishing-resistant authentication method! We recommend this only as a secondary method or for non-administrator users.
If you're using Salesforce Authenticator, the next time you go to log in, the system will walk you through entering a unique two-word phrase from your phone onto your computer to connect the app. Everything will be done via on-screen prompts!
This is not considered a phishing-resistant authentication method! We recommend this only as a secondary method or for non-administrator users.
To use another third-party app like Google Authenticator or Authy, the next time you log in and are prompted to verify your login, click "Having Trouble?"
Then click "Use a Different Verification Method"
Click "Use a Different Verification Method" again
Then select "Use verification codes from an authenticator app" and click Continue
Follow the on-screen instructions to connect the app to your PatronManager login
The system will walk you through scanning the code that appears on the screen in the app, which will connect the app to your login once you scan and click Connect.
If you're not able to scan the code, you can click "I Can't Scan the QR Code", which will give you a string of text you can type into the app instead.
What if I forget my phone, lose my phone, or get a new phone?
No need to worry! We've got some steps for you right here.





