To further mitigate data exfiltration risks, Salesforce is deploying a dynamic security control for UI report actions. When Salesforce detects significant deviations in a user's activity when running or viewing reports in Salesforce, the user must complete step-up Multi-Factor Authentication (MFA) to proceed.
For more info on the roadmap of upcoming targeted Security changes for the Salesforce Platform, see: Security-Related Product Updates to the Salesforce Platform.
Report Exports and large data queries are primary vectors for unauthorized data exfiltration. By leveraging machine learning to detect behavioral anomalies in near real-time, Salesforce can block potentially malicious exfiltration attempts by unauthorized actors before the data leaves the org.
Note: Salesforce rolls this change out via a gradual activation plan, starting with a report-only mode before full auto-containment actions.
All Salesforce users who access reports in sandbox and production orgs.
Most users will experience no change to their daily workflow.
However, if Salesforce detects anomalous behavior, the user sees these changes.
UI Sessions: The user is challenged with a Step-up MFA challenge on their next sensitive action (e.g., report export), even if they have recently performed Step-up MFA.
Note: If the user has not registered a Salesforce MFA verifier and lacks a valid email address or phone number, they will be unable to complete the Step-up MFA challenge on their next sensitive action (e.g., report export) and will be blocked from proceeding.
Review User Configuration: To ensure a smooth transition, confirm that all users, particularly those who use Single Sign-on (SSO), have configured at least one of these verification methods: a supported MFA verification method registered with Salesforce, a current email address, or SMS mobile phone registered to their login.
Failed Step-up Challenges: If a user can’t complete the Step-Up challenge, the user is denied access to the sensitive operation. Ensure that users have access to their MFA verification methods, registered email, or SMS phone number.
The control is mandatory for all users accessing Salesforce reports in sandbox and production orgs.
The current focus for the model is on UI-related report downloads.
|
Date |
Change |
|
May 5, 2026 |
Initial publication |
005321567

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.