Video | Tableau | Tool strategy

Setting up Multi-Factor Authentication on Tableau Online: Tableau with MFA

Salesforce is making MFA mandatory on Tableau Online from February, so here's exactly how to set it up without single sign-on.

Part ofTableau quick tips
Watch on YouTube
  • Salesforce is enforcing MFA on Tableau Online from February, with setup managed from the Users page rather than Settings
  • You can use the Salesforce Authenticator app or any standards-compliant authenticator like Authy or Google Authenticator to scan the QR code
  • Always scan the QR code from within the authenticator app itself, not your phone's camera, as the camera lacks the authentication capability
  • Generate and store recovery codes in a password manager in case your phone is lost, and name each device under MFA settings so you know which app is in use
  • You can manage MFA modes later via user settings to add a name or recovery codes

Salesforce is making multi-factor authentication mandatory on Tableau Online from February, and this walks through setting it up for an account without single sign-on, including registering an authenticator app and saving recovery codes.

Tim received a notice from Tableau that MFA would be enforced from February as part of a Salesforce-wide policy. He demonstrates the process for himself, on a Tableau Online site without single sign-on configured.

The Breakdown
  1. Why this is happening 0:00

    Salesforce is enforcing MFA across its platforms including Tableau Online from February, for consistency across the ecosystem. It's worth tracking down Tableau's own documentation on this, since the requirement covers two different paths: MFA with single sign-on and MFA without it.

  2. Turn on MFA from the Users page 1:55

    You enable MFA not from Settings but from the Users page — either via the three-dot menu on a user or by selecting users and going to Actions, then Authentication. You need to be a site or server admin to do this.

  3. Register an authenticator app via QR code 2:47

    After enabling MFA, the next login prompts you to register a verification method: either the Salesforce Authenticator app or any standards-based app like Google Authenticator or Authy. Scan the QR code from inside the authenticator app itself, not your phone's regular camera, since the camera doesn't have the authentication capability needed.

  4. Enter the generated code to confirm 4:22

    Once the app adds the account, it generates a rotating code (refreshing roughly every 30 seconds); enter that code back on the Tableau setup screen to link the two. From then on, logging in asks for a fresh code from the app each time.

  5. Grab recovery codes straight after setup 5:12

    Go into User Settings, then the MFA management area, to generate recovery codes — do this as a standalone step once the authenticator is linked. Store the codes somewhere safe like a password manager, since they're your way back in if you lose your phone and can't get a code.

  6. Name your device and manage methods later 5:22

    Give the authenticator entry a name so you know which device or app it corresponds to later. You can return to these settings any time to rename, add recovery codes, or swap authenticator methods, though adding a new app can remove the existing one.

  7. SSO and enterprise setups differ 7:05

    This walkthrough only covers accounts without single sign-on; if your organisation uses SSO or an enterprise authenticator (for example a Microsoft one), the setup steps will differ and aren't covered here.

Worth Knowing
  • MFA setup lives under the Users page, not Settings — easy to look in the wrong place first.
  • Scanning the QR code with your phone's normal camera won't work; it must be done inside the authenticator app.
  • Adding a second authenticator app can delete the existing one rather than running both side by side.
  • Authy backs up to the cloud and works across phone, watch and desktop, which makes recovering access after a lost phone easier — though recovery codes are still worth saving separately.
Use It When

Reach for this walkthrough when you're a Tableau Online site or server admin and need to get yourself or others compliant with the incoming MFA requirement, particularly if your site has no single sign-on set up.

How this Rollup was made provenance & method

A Rollup is drafted by AI from the video's transcript, then reviewed and edited by Tim. Everything used to produce this one is listed below — the model, the exact prompt, and the source video — so the process is transparent and reproducible.

Transcription
On-device — NVIDIA Parakeet v3 for recent videos, OpenAI Whisper large-v3 for earlier ones. The transcript never leaves the machine or gets published.
Drafting
Claude Sonnet 5 in the cloud, from that transcript.
Prompt
The exact Rollup prompt (v2) — the full system prompt, unedited.
Source video
Watch on YouTube
Drafted
5 July 2026 at 09:38
Reviewed & edited
5 July 2026 at 09:41 · by Tim Ngwena

Model + prompt + video is everything you'd need to recreate a Rollup like this yourself. The one thing we don't share is the transcript.

Rights. The video and its transcript are the property of TN Media Ltd. Unauthorised use or download is prohibited. © TN Media Ltd.