Loading

Prepare for Step-up Authentication in Anomalous Report Export

Udgivelsesdato: May 5, 2026
Beskrivelse

To further mitigate data exfiltration risks, Salesforce is deploying a dynamic security control for UI report actions. When Salesforce detects significant deviations in a user's activity when running or viewing reports in Salesforce, the user must complete step-up Multi-Factor Authentication (MFA) to proceed.

For more info on the roadmap of upcoming targeted Security changes for the Salesforce Platform, see: Security-Related Product Updates to the Salesforce Platform.

Why Is Salesforce Making This Change

Report Exports and large data queries are primary vectors for unauthorized data exfiltration. By leveraging machine learning to detect behavioral anomalies in near real-time, Salesforce can block potentially malicious exfiltration attempts by unauthorized actors before the data leaves the org.

When Does This Change Take Effect

  • Sandboxes: Starting June 22, 2026
  • Production: Starting July 13, 2026

Note: Salesforce rolls this change out via a gradual activation plan, starting with a report-only mode before full auto-containment actions.

Who's Affected

  • All Salesforce users who access reports in sandbox and production orgs.

What to Expect

Most users will experience no change to their daily workflow. 

However, if Salesforce detects anomalous behavior, the user sees these changes.

  • UI Sessions: The user is challenged with a Step-up MFA challenge on their next sensitive action (e.g., report export), even if they have recently performed Step-up MFA.

Note: If the user has not registered a Salesforce MFA verifier and lacks a valid email address or phone number, they will be unable to complete the Step-up MFA challenge on their next sensitive action (e.g., report export) and will be blocked from proceeding.

Løsning

Before Enforcement: How to Prepare

  • Review User Configuration: To ensure a smooth transition, confirm that all users, particularly those who use Single Sign-on (SSO), have configured at least one of these verification methods: a supported MFA verification method registered with Salesforce, a current email address, or SMS mobile phone registered to their login.

After Enforcement: Resolve Errors

  • Failed Step-up Challenges: If a user can’t complete the Step-Up challenge, the user is denied access to the sensitive operation. Ensure that users have access to their MFA verification methods, registered email, or SMS phone number.

Common Questions

Is this a mandatory feature?

 The control is mandatory for all users accessing Salesforce reports in sandbox and production orgs. 

Does this new model cover all data exfiltration activities?

The current focus for the model is on UI-related report downloads.

 

Change Log

Date

Change

May 5, 2026

Initial publication

 

Vidensartikelnummer

005321567

 
Indlæser
Salesforce Help | Article