Loading

Prepare for Step-up Authentication in Anomalous Report Export

Publiseringsdato: Jul 14, 2026
Beskrivelse

To further mitigate data exfiltration risks, Salesforce is deploying a dynamic security control for UI report actions. When Salesforce detects significant deviations in a user's activity when running or viewing reports in Salesforce, the user must complete step-up Multi-Factor Authentication (MFA) to proceed.

For more info on the roadmap of upcoming targeted Security changes for the Salesforce Platform, see: Security-Related Product Updates to the Salesforce Platform.

Watch: Video Resource

To get an overview of the Step-up Authentication requirement, watch this video below or click the link to open the video in a new tab: Salesforce Step-Up Authentication

Why Is Salesforce Making This Change

Report Exports and large data queries are primary vectors for unauthorized data exfiltration. By leveraging machine learning to detect behavioral anomalies in near real-time, Salesforce can block potentially malicious exfiltration attempts by unauthorized actors before the data leaves the org.

When Does This Change Take Effect

  • Sandboxes: Starting July 6, 2026
  • Production: Starting July 27, 2026

Note: Salesforce rolls this change out via a gradual activation plan, starting with a report-only mode before full auto-containment actions.

Who's Affected

  • All Salesforce users who access reports in sandbox and production orgs.

  • External Experience Cloud users (customers, partners, and community members accessing Salesforce through an Experience Cloud site) are fully exempt from step-up authentication. Step-up will not be triggered for these sessions.

What to Expect

Most users will experience no change to their daily workflow. 

However, if Salesforce detects anomalous behavior, the user sees these changes.

  • UI Sessions: The user is challenged with a Step-up MFA challenge on their next sensitive action (e.g., report export), even if they have recently performed Step-up MFA.

Note: If the user has not registered a Salesforce MFA verifier and lacks a valid email address or phone number, they will be unable to complete the Step-up MFA challenge on their next sensitive action (e.g., report export) and will be blocked from proceeding.

Løsning

Before Enforcement: How to Prepare

  • Review User Configuration: To ensure a smooth transition, confirm that all users, particularly those who use Single Sign-on (SSO), have configured at least one of these verification methods: a supported MFA verification method registered with Salesforce, a current email address, or SMS mobile phone registered to their login.

After Enforcement: Resolve Errors

  • Failed Step-up Challenges: If a user can’t complete the Step-Up challenge, the user is denied access to the sensitive operation. Ensure that users have access to their MFA verification methods, registered email, or SMS phone number.

Common Questions

Is this a mandatory feature?

 The control is mandatory for all users accessing Salesforce reports in sandbox and production orgs. 

Does this new model cover all data exfiltration activities?

The current focus for the model is on UI-related report downloads.

 

Change Log

Date

Change

July 14th, 2026

Noted that External Experience Cloud users(customers, partners, and community members accessing Salesforce through an Experience Cloud site) are fully exempt from step-up authentication. Step-up will not be triggered for these sessions.

July 7, 2026

Sandbox and Prod rollout dates adjusted:

  • Sandbox enforcement now July 6, 2026 (was June 29, 2026)
  • Production enforcement now July 27, 2026 (was July 13, 2026)

June 30, 2026

Embedded video player in the article

June 24, 2026

Updated Sandbox release starting date from June 22 to June 29, 2026

May 5, 2026

Initial publication

 

Knowledge-artikkelnummer

005321567

 
Laster
Salesforce Help | Article