제품 및 기술

Snowflake Expands Supported MFA Methods and Makes Them Available by Default Everywhere

Digital illustration of a security icon overlaid on a world map

Earlier this year, we announced a multiphased plan to block single-factor password sign-ins. Starting in May, multi-factor authentication (MFA) will be enforced on all password sign-ins to Snowsight UI for human users as part of BCR 2025_04. Password sign-ins outside of Snowsight, such as those in BI tools like PowerBI, will be exempted from this policy. However, this exemption is temporary and will be lifted by March 2026, when Snowflake will enforce MFA on all surfaces. The MFA enforcement on Snowsight rollout will follow the Snowflake Behavior Change Management process. 

We are also announcing the general availability of new MFA methods: authenticator apps and passkeys. To support existing business intelligence apps that don’t yet support MFA login, we are launching programmatic access tokens (PATs) as a drop-in replacement for passwords. 

Note that Snowsight MFA enforcement will not affect single sign-on users using SAML or OAuth, or legacy service users. Managed accounts and trial accounts are not included in this rollout. 

Addressing customer MFA concerns with new capabilities 

To better understand the challenges of enabling MFA, we interviewed more than 100 customers. These conversations identified two key product enhancements:

  • Alternative MFA methods: Customers told us that they want to be able to use their existing, approved MFA methods with Snowflake.

  • Solution for business intelligence apps that do not currently support MFA: Customers asked us to provide a solution for applications that support only passwords.

We are happy to announce general availability of four products that address these concerns:

  • Support for passkeys: Based on the industry-wide standards established by FIDO, passkeys allow signing into Snowflake with the same process that users use to unlock their device (biometrics, PIN, security keys). Note that passkeys are supported only as a secondary authentication factor in addition to username and password.

Screenshot of touch ID MFA app
  • Support for authenticator apps: Based on the industry standard Time-Based One-Time Password (TOTP), users can now use their existing approved authenticator apps (like Microsoft or Google authenticator apps) to access Snowflake via MFA.
Screenshot of an authenticator app used for MFA
  • Support for programmatic access tokens: We introduced PATs as a solution for programmatic access to Snowpark Container Services (SPCS) and Snowflake REST APIs. PATs can also be a drop-in replacement for passwords for apps that support only username and password authentication. PATs raise the security bar because by default they are tied to specific roles, have an expiration date and must be used in tandem with a network policy. We recommend creating separate PATs for different use cases to minimize the blast radius in case of PAT compromise.
Screenshot of programmatic access token
  • Support for OAuth in Snowflake drivers: To simplify migration to federation, we are introducing native support for OAuth in ODBC, JDBC and Python drivers (all generally available). We plan to expand this support to all other drivers in the upcoming months. By using Snowflake OAuth alongside the new “local application” OAuth configuration, the drivers can natively support new MFA methods, including passkeys and authenticator apps.

What should you do?

Check the list of affected users in your Snowflake account by visiting the new Risky Human User scanner in the Trust Center Threat Intel package. We recommend following our best practices for migration from single-factor authentication to mitigate any findings. If you have concerns or questions, please reach out to your account representative or contact Snowflake support. 

What’s next?

As announced previously, Snowflake will deprecate single-factor password sign-ins soon. Get ahead of the curve and start your user migration today by following our best practices for migration from single-factor authentication. 

Forward Looking Statements

This article contains forward-looking statements, including about our future product offerings, and are not commitments to deliver any product offerings. Actual results and offerings may differ and are subject to known and unknown risk and uncertainties. See our latest 10-Q for more information.

 

Resources

Best Practices for Migration from Single-Factor Authentication

Learn how to leverage Snowflake capabilities to enforce strong authentication and mitigate the risks of credential theft.
기사 공유하기

Shared Destiny with Snowflake Horizon Catalog Built-In Security

Through Horizon Catalog security capabilities, empower security admins and CISO’s to better protect environments and centralize threat monitoring and RBAC.

Meta’s Llama 4 Large Language Models Now Available on Snowflake Cortex AI

We’re pleased to bring Meta’s latest Llama 4 models to Snowflake Cortex AI!

Snowflake 최신 보안 혁신 소식: 데이터 및 AI를 위한 선제적 보안 및 엔터프라이즈 수준의 심층 방어 기능 추가

신뢰할 수 있는 AI 데이터 클라우드 구축을 위해 설계된 MFA, 악성 IP 보호, 프라이빗 연결 등 Snowflake의 최신 보안 혁신 기능을 살펴보세요.

Snowflake Reinforces Commitment to Bringing Efficiency and Security-Driven Platforms to the Military and Defense Ecosystem with DOD IL5

Snowflake attains DOD IL5 Provisional Authorization, enabling secure, compliant data solutions for national security and the defense industrial base.

Empowering Data Engineering Today for Tomorrow’s Challenges

Empower data engineers with the tools to build efficient pipelines, integrate AI and prepare your data stack for the future in an increasingly complex tech landscape.

Snowflake Startup Spotlight: DeepTempo

DeepTempo는 딥러닝과 Snowflake를 사용하여 위협 감지를 강화하고 오탐을 줄이고 원활한 보안 통합을 가능하게 함으로써 사이버 보안을 혁신합니다.

Snowflake Will Automatically Disable Leaked Passwords Detected on the Dark Web

Snowflake는 Leaked Password Protection (LPP)를 통해 보안을 강화하고, 다크웹에서 발견된 암호를 자동으로 모니터링하고 비활성화합니다.

Snowflake Openflow, AI와 상호운용성을 위한 데이터 이동 혁신

Snowflake Openflow는 확장 가능한 관리형 플랫폼을 통해 여러 소스와 형식에 걸쳐 데이터 통합을 간소화합니다. Snowflake Openflow는 현재 AWS에서 BYOC를 통해 GA로 제공됩니다.

An Even Easier-to-Use and More Trusted Platform from Snowflake

Learn how new Snowflake updates make the platform even easier to use and more trusted — boosting automation, security, governance and AI readiness at scale.

Subscribe to our blog newsletter

Get the best, coolest and latest delivered to your inbox each week

Where Data Does More

  • 30일 무료 평가판
  • 신용카드 불필요
  • 언제든지 취소 가능