To further mitigate data exfiltration risks, Salesforce is deploying a dynamic security control for UI report actions. When Salesforce detects significant deviations in a user's activity when running or viewing reports in Salesforce, the user must complete step-up Multi-Factor Authentication (MFA) to proceed.
For more info on the roadmap of upcoming targeted Security changes for the Salesforce Platform, review "Security-Related Product Updates to the Salesforce Platform" in Additional Resources.
This section explains how to prepare for the Salesforce step-up authentication requirement for anomalous report activity, who is affected, when it takes effect, and how to resolve failed challenges.
To get an overview of the Step-up Authentication requirement, watch the video below or open it in a new tab: Salesforce Step-Up Authentication
Report exports and large data queries are primary vectors for unauthorized data exfiltration. By leveraging machine learning to detect behavioral anomalies in near real-time, Salesforce can block potentially malicious exfiltration attempts by unauthorized actors before the data leaves the org.
Note: Salesforce rolls this change out via a gradual activation plan, starting with a report-only mode before full auto-containment actions.
Most users experience no change to their daily workflow. However, if Salesforce detects anomalous behavior, the user sees these changes:
Note: If the user has not registered a Salesforce MFA verifier and lacks a valid email address or phone number, the user cannot complete the Step-up MFA challenge on their next sensitive action (for example, a report export) and is blocked from proceeding.
The control is mandatory for all users accessing Salesforce reports in sandbox and production orgs.
The current focus for the model is on UI-related report downloads.
| Date | Change |
| July 14, 2026 | Noted that External Experience Cloud users (customers, partners, and community members accessing Salesforce through an Experience Cloud site) are fully exempt from step-up authentication. Step-up is not triggered for these sessions. |
| July 7, 2026 | Sandbox and Production rollout dates adjusted. Sandbox enforcement is now July 6, 2026 (was June 29, 2026). Production enforcement is now July 27, 2026 (was July 13, 2026). |
| June 30, 2026 | Embedded video player in the article |
| June 24, 2026 | Updated Sandbox release starting date from June 22 to June 29, 2026 |
| May 5, 2026 | Initial publication |
005321567

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.