What changes
Password-authenticated human users must use multi-factor authentication. Non-human users must move away from password authentication to supported key-pair, OAuth or workload-identity methods. Legacy service users are migrated to the SERVICE user type.
Who is affected
- Human users who still authenticate with a password but no second factor.
- Service accounts and automated clients using passwords.
- Administrators whose provisioning workflows still create legacy service users.
Timeline
Final enforcement is being rolled out account by account from August through October 2026. Snowflake communicates the exact enforcement date for each account separately.
Required action
- Inventory password-authenticated users and service accounts.
- Enrol human users in MFA.
- Move machine identities to supported non-password authentication.
- Update provisioning automation for the SERVICE user type.
What is not established
The public rollout documentation does not provide one global enforcement day or disclose the schedule for every individual account.
PlatformTrace analysis
This is a material authentication enforcement event because unchanged integrations may fail once the account-specific enforcement date arrives.
Sources
Corrections and updates
No correction is currently open. Account-level rollout changes will be recorded as dated updates.