Loading

Prepare for Step-up Authentication in Anomalous Report Export

Дата публикации: Jun 30, 2026
Описание

To further mitigate data exfiltration risks, Salesforce is deploying a dynamic security control for UI report actions. When Salesforce detects significant deviations in a user's activity when running or viewing reports in Salesforce, the user must complete step-up Multi-Factor Authentication (MFA) to proceed.

For more info on the roadmap of upcoming targeted Security changes for the Salesforce Platform, see: Security-Related Product Updates to the Salesforce Platform.

Watch: Video Resource

To get an overview of the Step-up Authentication requirement, watch this video below or click the link to open the video in a new tab: Salesforce Step-Up Authentication

Why Is Salesforce Making This Change

Report Exports and large data queries are primary vectors for unauthorized data exfiltration. By leveraging machine learning to detect behavioral anomalies in near real-time, Salesforce can block potentially malicious exfiltration attempts by unauthorized actors before the data leaves the org.

When Does This Change Take Effect

  • Sandboxes: Starting June 29, 2026
  • Production: Starting July 13, 2026

Note: Salesforce rolls this change out via a gradual activation plan, starting with a report-only mode before full auto-containment actions.

Who's Affected

  • All Salesforce users who access reports in sandbox and production orgs.

What to Expect

Most users will experience no change to their daily workflow. 

However, if Salesforce detects anomalous behavior, the user sees these changes.

  • UI Sessions: The user is challenged with a Step-up MFA challenge on their next sensitive action (e.g., report export), even if they have recently performed Step-up MFA.

Note: If the user has not registered a Salesforce MFA verifier and lacks a valid email address or phone number, they will be unable to complete the Step-up MFA challenge on their next sensitive action (e.g., report export) and will be blocked from proceeding.

Решение

Before Enforcement: How to Prepare

  • Review User Configuration: To ensure a smooth transition, confirm that all users, particularly those who use Single Sign-on (SSO), have configured at least one of these verification methods: a supported MFA verification method registered with Salesforce, a current email address, or SMS mobile phone registered to their login.

After Enforcement: Resolve Errors

  • Failed Step-up Challenges: If a user can’t complete the Step-Up challenge, the user is denied access to the sensitive operation. Ensure that users have access to their MFA verification methods, registered email, or SMS phone number.

Common Questions

Is this a mandatory feature?

 The control is mandatory for all users accessing Salesforce reports in sandbox and production orgs. 

Does this new model cover all data exfiltration activities?

The current focus for the model is on UI-related report downloads.

 

Change Log

Date

Change

June 30, 2026

Embedded video player in the article

June 24, 2026

Updated Sandbox release starting date from June 22 to June 29, 2026

May 5, 2026

Initial publication

 

Номер статьи базы знаний

005321567

 
Загрузка
Salesforce Help | Article