September 2026 - Build 1.4.6

Prev Next

Table of Contents

📋 At a glance

This release lets Salesforce administrators sign in to the Mobile Check-in App when their org enforces phishing-resistant multi-factor authentication. Salesforce began enforcing this for privileged users on 1 July 2026, and administrators whose only registered MFA method is a passkey could not get past the app's login screen. The app now offers Login for Admin, which completes the passkey sign-in in the device's browser.

This release raises the minimum iOS version to iOS 17. Devices on iOS 16 cannot run Build 1.4.6 and will stay on their current build. iOS 1.4.6 · Android 1.4.6.

For iOS users, this is the first update since Build 1.4.3. Builds 1.4.4 and 1.4.5 were released on Android only, so iOS devices receive all three sets of changes at once. Read the Build 1.4.4 and Build 1.4.5 notes alongside this one.

Update What it does For whom Setup
🔑 Login for Admin Administrators with passkey-only MFA can sign in, through a browser-based login flow Salesforce admins, privileged users App update
📱 iOS 17 minimum Salesforce Mobile SDK 13.2.1 requires iOS 17; iOS 16 devices can no longer update All iOS users Check device OS versions

Update the app from the App Store or Google Play. Released 8 September 2026 as an emergency release. It contains one change, the Salesforce Mobile SDK upgrade below.


✨ What's new

🔑 Administrators with a passkey can sign in again

Salesforce's phishing-resistant MFA enforcement, which began rolling out to production orgs on 1 July 2026, requires privileged users to authenticate with a passkey, a built-in authenticator or a security key. Authenticator apps that generate time-based codes (Salesforce Authenticator, Google Authenticator, Microsoft Authenticator) are no longer accepted for those users.

The app's login screen previously ran inside an embedded web view, which cannot perform a passkey ceremony. An administrator whose only registered method was a passkey was stuck: the passkey button did nothing and no code-entry fallback appeared. This affects the official Salesforce Mobile app in the same way, so it is a platform constraint rather than a Blackthorn configuration problem.

The login screen now offers Login for Admin, which hands the sign-in to the device's browser where the passkey ceremony can complete. Choose it if your Salesforce user is an administrator or another privileged user and your MFA is a passkey.

One thing to note: sign-in with an authenticator app is unchanged. Users who are not subject to the enforcement continue to use the standard login. Salesforce decides which users the requirement applies to; the app does not need to be told who is an administrator.

📱 iOS 17 is now the minimum

Salesforce Mobile SDK 13.2.1 requires iOS 17.0, so the app's minimum has been raised from iOS 16. An iPhone or iPad on iOS 16 will not receive Build 1.4.6 and will remain on the build it has. Before rolling this out, check the OS version on the devices your team uses for check-in, particularly older shared hardware kept on an earlier iOS release. Android is unaffected: Android 9 (API 28) remains the minimum.


⚙️ Requirements

iOS iOS 17.0 or later: raised from iOS 16.0 in this release
Android Android 9 (API 28) or later: unchanged
Events managed package No change (5.55 or later for walk-up registration Event Items)
Salesforce MFA Privileged users must have a phishing-resistant method registered. Salesforce does not enroll them for you, so a user with no such method registered may still be unable to sign in. [confirm with Support what the enrollment path is for that user]

⬆️ How to upgrade

Update the Blackthorn Mobile Check-in App from the Apple App Store or the Google Play Store. On iOS, confirm your devices are on iOS 17 or later first.

If you are an administrator and sign-in still fails after updating, check that a phishing-resistant MFA method is registered on your Salesforce user, then use Login for Admin on the login screen. Learn more in Install the Mobile Check-in App.