Loading

Security-Related Product Updates to the Salesforce Platform: User Identity, Data Protection, and Access Controls

Publiseringsdato: Jul 10, 2026
Beskrivelse

This page serves as the ongoing roadmap for critical product changes to the Salesforce Platform that impact your Salesforce Org's security. Our intention is to provide you with the necessary lead time, technical clarity, and architectural guidance to maintain the security of your data as these changes are rolled out. Please note that this roadmap focuses on specific features designed to minimize risk from phishing attacks, data exfiltration, and account takeover attempts; It is evolving and not inclusive of all Salesforce security-related changes.

Find details for each planned change in the table below. 

Not a Salesforce admin? Jump to the next section to see what’s changing for you.

Security Control

Enforcement Timeline(s)

Knowledge Article / Resources

Email Domain Verification

Phase 1: New Email-Sending Domains and Existing Domains 

  • Sandboxes: March 24 – April 25, 2026

  • All other orgs (including Production): May 5 – June 1, 2026

Phase 2: Enforcement for Allowlisted Domains

  • Sandboxes: June 29 – July 27, 2026

  • All other orgs (including Production): June 29 – July 27, 2026

Preventing Connections from Anonymizing VPNs, Proxies and High-Risk IP Addresses

  • Connected App or API usage - enforcement applied starting April 24, 2026

Extended Login Anomaly Detections and Containment

  • Enforcement applied early April 2026

Phishing-Resistant MFA Enforcement for Privileged Users, Including Admins

MFA Enforcement for All Employee Users

Step-up Auth for Report Activities (Time Based Session Level Policy)

  • Available in Sandboxes: Starting May 27, 2026, staggered over approximately 7 days

  • Available in Production: Starting May 27, 2026,  staggered over approximately 15 days

  • Enforced in Sandboxes: Starting June 17, 2026, staggered over approximately 7 days

  • Enforced in Production: Starting July 1, 2026, staggered over approximately 30 days

Step-up Authentication for Anomalous Behavior

  • Sandboxes: June 29, 2026

  • Production: July 13, 2026

Transaction Security Policy Enhancements

  • Available in Sandboxes: Starting June 1, 2026

  • Available in Production: Starting June 15, 2026

  • Enforced in Sandboxes: Starting June 22, 2026

  • Enforced in Production: Starting July 13, 2026



Not a Salesforce admin? Here’s what’s changing for you. 

Starting in June 2026, Salesforce enforces new security requirements that can affect your login and report export experiences. These security changes secure your account and your company’s data against unauthorized access.

Multi-factor authentication (MFA) is required to log in

  1. What is MFA? MFA protects access to your Salesforce account during login by requiring two or more pieces of information to prove your identity. The first piece is something you know: your username and password. The second piece is something you have: an MFA verification method that confirms your identity, such as a passkey (built-in authenticator or security key) or a code from an authenticator app on your phone. To learn more about MFA and its security benefits, see What Is Multi-Factor Authentication? 

  2. I log in from another site, such as Google, using single sign-on (SSO). How does my experience change? Contact your admin for more information. 

  3. I log in with my username and password. How does my experience change? If you don’t have an MFA verification method, Salesforce asks you to register one after you log in. The MFA method that you use depends on your company’s policies. 

  4. How can I prepare for this change? Register an MFA verification method. To see what MFA methods you can use, contact your admin.  

Step-up authentication is required for report actions

  1. What is step-up authentication? Step-up authentication is an extra identity check for sensitive actions, such as attempts to access your company’s data. With this change, Salesforce requires you to verify your identity to view and export reports. For example, Salesforce asks you to use a passkey to export a report.

  2. I log in from another site (SSO) using a non-Salesforce MFA method. Can I use this method for step-up authentication? No. You can use a Salesforce MFA method, or you can receive a verification code via phone or email.

  3. How can I prepare for this change? Register an MFA verification method and review your phone number and email address. To understand what MFA methods you can use, contact your admin.

 

Løsning

Change Log

Date

Change

July 10, 2026

Sandbox Enforcement Timeline Updated for both Phishing-Resistant MFA Enforcement for Privileged Users, Including Admins and MFA Enforcement for All Employee Users:  Enforcement for the Sandbox [Preview] Release Group has been rescheduled to July 10, 2026 (moved from July 6-8) following an incident where some users reported being unable to log in after MFA enforcement was applied. The "Create a Passkey" prompts users experienced are expected behavior as described in Improved Experience for Passkey Registration and Login. This was not a product defect.

July 8, 2026

Added a note on the MFA for All Employee Users and Phishing-Resistant MFA enforcement timelines that the detailed Release Group Enforcement schedule is now published in respective knowledge articles, replacing previous verbiage about the staggered timeline.

July 2, 2026

Salesforce determined the plan to resume the following enforcement changes, and detailed the new schedule.

Phishing-Resistant MFA for Privileged Users, including Admins

  • Sandbox: Enforcement now scheduled to start July 6, 2026 (moved from June 22), staggered over a 2-day window.

  • Production: Enforcement scheduled to start July 20, 2026 (moved from July 1), staggered over a 15-day window.

MFA for All Employee Users

  • Sandbox: Enforcement now scheduled to start July 6, 2026 (moved from June 22), staggered over a 2-day window.

  • Production: Enforcement scheduled to start July 20, 2026 (unchanged), staggered over a 15-day window.

July 1, 2026

Salesforce has placed the Phishing-Resistant MFA Enforcement for Privileged Users, Including Admins and MFA Enforcement for All Employee Users changes on hold. Plans to resume will be announced soon.

June 24, 2026

Updated release dates:

Step-up Authentication for Anomalous Behavior

  •  Sandboxes - moved from June 22 to June 29, 2026

Email Domain verification -
Phase 1: New Email-Sending Domains and Existing Domains

  • Sandboxes - moved from April 10, 2026 to March 24 - April 25, 2026
  • All other orgs (including Production): moved from starting April 13, 2026 to May 5 -  June 1, 2026 

Phase 2: Enforcement for Allowlisted Domains

  • Sandboxes: moved from starting April 14, 2026  to starting June 29 - July 27, 2026)
  • All other orgs (including Production): previously TBD, updated to June 29 - July 27, 2026

June 2, 2026

Step-up Auth for Report Activities (Time Based Session Level Policy) enforcement dates for Sandboxes and Production updated.

May 6, 2026

Added section for end-users "Not a Salesforce Admin? Here's what's changing for you."

May 5, 2026

Replaced prior announcement "Prepare for New Security Control Requirements in June 2026" with the targeted Security Roadmap table of changes.

March 26, 2026

Initial publication

 

Knowledge-artikkelnummer

005317465

 
Laster
Salesforce Help | Article