Independent enterprise technology-change research

PT-2026-028 · 17 July 2026

PlatformTrace

Enterprise platform migrations, examined in public.

Authentication enforcement · Scheduled · High confidence

Snowflake requires strong authentication for all users

Snowflake is enforcing stronger authentication across customer accounts between August and October 2026, ending password-only access for human users and password authentication for non-human users.

Evidence boundary: Each Snowflake account receives its own enforcement date. This record does not imply that every customer changes on one universal day.

What changes

Password-authenticated human users must use multi-factor authentication. Non-human users must move away from password authentication to supported key-pair, OAuth or workload-identity methods. Legacy service users are migrated to the SERVICE user type.

Who is affected

  • Human users who still authenticate with a password but no second factor.
  • Service accounts and automated clients using passwords.
  • Administrators whose provisioning workflows still create legacy service users.

Timeline

Final enforcement is being rolled out account by account from August through October 2026. Snowflake communicates the exact enforcement date for each account separately.

Required action

  • Inventory password-authenticated users and service accounts.
  • Enrol human users in MFA.
  • Move machine identities to supported non-password authentication.
  • Update provisioning automation for the SERVICE user type.

What is not established

The public rollout documentation does not provide one global enforcement day or disclose the schedule for every individual account.

PlatformTrace analysis

This is a material authentication enforcement event because unchanged integrations may fail once the account-specific enforcement date arrives.

Sources

  1. Snowflake strong-authentication rollout documentation.

Corrections and updates

No correction is currently open. Account-level rollout changes will be recorded as dated updates.