Skip to main content

Multi-Factor Authentication (MFA) Explained

Understand what Multi-Factor Authentication (MFA) is, why Blackpurl requires it, and how it protects your dealership's data.

Multi-Factor Authentication (MFA) is a security feature that requires users to prove their identity in more than one way before gaining access to a system. Blackpurl requires MFA for all users to protect customer data and comply with platform and regulatory requirements.

What Is Multi-Factor Authentication (MFA)?

MFA adds layers of protection that help prevent malicious attackers from accessing your system — even if they have your password. Instead of relying on a single proof of identity, MFA requires two or more independent forms of verification.

The first factor is typically your username and password. After that, you are prompted for a second form of proof that is different in nature from the first. This matters because if your password has been compromised, a second password could be too — so MFA requires a fundamentally different type of verification.

Common second factors include:

  • A time-sensitive code generated by an authenticator app

  • A scanned fingerprint or biometric verification

  • A physical security key you plug into your computer

Each of these different forms of proof is called a factor — which is where the name Multi-Factor Authentication comes from.

MFA vs. Two-Factor Authentication (2FA)

MFA and two-factor authentication (2FA) are related but not identical. Here is the difference:

  • 2FA — requires exactly two forms of proof

  • MFA — requires two or more forms of proof, and tends to be stricter about what qualifies as a valid second factor

For example, a code sent by text message is commonly used in 2FA, but many MFA implementations do not consider SMS messages secure enough to count as a valid second factor. Blackpurl's MFA does not use text messages for this reason.

Think of MFA as the cybersecurity equivalent of two pieces of ID, please.

Why Blackpurl Requires MFA

Blackpurl operates on the Salesforce platform, which mandates that all users logging into a Salesforce organization must use MFA. This is not optional — it is a platform-wide requirement.

Beyond the platform requirement, MFA keeps customer data safe — something every dealership has a direct interest in protecting.

FTC Safeguards Rule (USA Dealerships)

For dealerships in the United States, MFA is also required under the Federal Trade Commission (FTC) Safeguards Rule, which governs how businesses must protect customer information. Further details are available on the FTC website.

An important point from the FTC rule is that the definition of Financial Institution is broader than most people expect. If your dealership facilitates financing or leasing for a customer in any capacity — even if your dealership is not actually providing the financing — you are considered a Financial Institution under the rule.

MFA is listed among the required obligations under the Safeguards Rule. Notably, even the size exception (dealerships with fewer than 5,000 customers) still requires MFA, meaning smaller dealerships are also subject to this requirement.

Why MFA Matters Regardless of Location

Even for dealerships outside the USA or those operating on a cash-only basis where the FTC Safeguards Rule does not directly apply, MFA remains a mandatory feature in Blackpurl. Operating without a foundational security precaution like MFA exposes your dealership to data breaches and significant legal liability if a breach occurs. The growing number of software providers — including Salesforce — requiring MFA reflects how serious this risk is.

Setting Up MFA

To use MFA in Blackpurl, your dealership must set up an authenticator app or device. For instructions on your options and how to get started, see Multi-Factor Authentication (MFA) Authenticator Setup for Blackpurl.

Did this answer your question?