Loading

Mandatory IP Allowlisting in Marketing Cloud Engagement

Publiceringsdatum: Sep 4, 2026
Beskrivning

To enhance the security of the Salesforce platform, Salesforce will require that all Marketing Cloud Engagement accounts use the login IP allowlist in blocking mode. This security control prevents unauthorized UI and API access to your account.

This rollout involves two stages with different schedules: 

  1. Initial availability of Salesforce generated recommended IP ranges for admins to review and accept. See the Availability of Recommended Baseline IP Lists  below. 

  2. Salesforce automatically enforces the “Log Violation and Deny Access” (blocking mode) settings when customers have not already enabled. This control will be enforced in a phased rollout over the coming months, and affected customers will receive communications prior to their specific enforcement dates.   

We highly recommend that customers proactively prepare by reviewing and accepting Salesforce-recommended IP ranges, enabling “Log Allowlist Violations” (monitoring mode) to refine their ranges, and ultimately enabling blocking mode themselves to avoid disruption.


What’s Changing

Stage 1) Salesforce Recommended IP Ranges Initial Availability: Salesforce provides a recommended list of IP ranges for admins to review and accept. These suggestions are based on successful authentications from the past six months, excluding known malicious addresses. Note that Salesforce’s recommendations are only available if the total is under 100 unique IP ranges. Salesforce-suggested IP ranges don't override any IP ranges already configured in the allowlist. 

 

Stage 2) IP Allowlist Blocking Mode Enforcement. By January , 2027,  Salesforce will mandate Log Violation and Deny Access (blocking mode) in accounts where it isn't enabled. When this setting is on, users can log in only from IP addresses on the allowlist. Review and validate the recommended IP ranges, and use Log Allowlist Violations (monitoring mode) to test and refine IP ranges.

 

There is no change for accounts that already use blocking mode with the login IP allowlist.

Why Is Salesforce Making This Change

To uplift the security of the Salesforce platform, we are mandating the use of IP allowlisting in enforcement mode by all Marketing Cloud Engagement customers. This security tool contains and prevents the recurrence of security incidents.

 

When Does Enforcement Take Effect

Customers will be notified via email when an enforcement date has been set for their instance to enable blocking mode.

Who’s Affected

This change affects Marketing Cloud Engagement customers whose IP allowlist is not enabled or is set to monitoring-only mode at the enterprise or business unit level. 

What to Expect With IP Allowlist Blocking Mode Enforcement

Salesforce is enforcing this security control in phases. We will notify you by email when an enforcement date is set for your account.

Enterprise (EID) Level: We will enable blocking mode for your EID.

  • If your EID is already in Log Violations and Deny Access (blocking mode), your settings don't change.

  • If your EID is in IP Allowlisting Disabled or currently has no IP list, we will enable blocking mode and apply Salesforce-recommended baseline IP ranges.

  • If your EID is in Log Allowlist Violations (monitoring mode), we will enable blocking mode, keep your existing list, and append Salesforce-recommended IP ranges to ensure continued access.

Business Unit (MID) Level: We will enable blocking mode for BUs that have a current business unit level configuration. 

  • If your BU is already in blocking mode, your settings don't change.

  • If your BU is in monitoring mode, we will switch it to blocking mode and append Salesforce-recommended IP ranges to your existing IP list.

  • If the allowlist is disabled in your BU, we will switch it to blocking mode with the Enterprise level list source.

All other business units inherit the enterprise-level IP allowlist configuration.
Note: The recommendations are provided at the EID level, not at the individual BU level.

Lösning

How to Prepare

Thoroughly review, validate, and accept the Salesforce-generated IP allowlist recommendations. 

For best results, turn on monitoring mode for at least two weeks before you move to blocking mode.  

This step helps identify and add legitimate IP addresses that are missing from your allowlist without blocking user access.

Maintain your Allowed IP Ranges 

Regularly review and maintain your login IP allowlist. Review your IP allowlist access logs to identify and add denied IPs that are legitimate.

Common Questions

  • What does “blocking mode” mean?
    Users can log in only from IP addresses on the allowlist. The Access Log tracks login attempts from IP addresses that aren’t on the allowlist. To enable this feature, select “Log Violations and Deny Access” in the Security Settings. Refer to Enable the Login IP Allowlist.

  • Does this apply to UI Login and/or API access?
    Yes, IP allowlisting applies to both UI Login and API access.

  • Are cross-cloud IPs impacted?
    No, cross-cloud IPs are not impacted by this feature.

  • Can I opt-out?
    Currently, customers cannot opt-out from the enforcement of this feature.

  • Our organization accesses Marketing Cloud Engagement from public cloud infrastructure or has a large number of remote employees. How can we add all of the IP ranges that will access our account?
    In situations where your organization accesses Marketing Cloud Engagement from many different IP ranges, we recommend that you use one of these strategies:

    • Static cloud egress: Configure the cloud environment so that outbound traffic to the Marketing Cloud Engagement API exits through a provider-managed static public IP address, such as an Elastic IP.

    • Dedicated egress proxy: Route Marketing Cloud Engagement API traffic through a proxy or API gateway that has a static public IP address. 

    • Corporate VPN: Route Marketing Cloud Engagement API traffic through a corporate VPN so requests exit through your organization's known, static public IP range.

    • Centralized cloud NAT or egress gateway: Consolidate outbound traffic from multiple cloud workloads behind a known IP range or small set of static IPs.

    • Enterprise gateway: If API traffic already passes through an enterprise API gateway, enterprise service bus, or integration gateway, configure that gateway to use stable outbound IP addresses for traffic to Marketing Cloud Engagement.

    • Stable IP ranges: If your cloud or network provider supplies a predictable range of outbound addresses, use the smallest appropriate CIDR range rather than maintaining a large list of individual addresses.

Change Log

Date

Change

September 4, 2026

  • Removed ‘Timeline for Reviewing the Pre-Compiled List of Recommended IP Addresses’ section as the recommendation dates have passed

  • Removed The FAQ related to availability of IP recommendations

  • Added a note to clarify where the recommendations can be seen and verified

  • Added a FAQ to address large IP range query

July 31, 2026

  • Updated the title of the table to "Availability of Recommended Baseline IP Lists".

  • Relocated the "When Does Enforcement Take Effect" section to before the table.

  • Inserted a new clarification: Note : The dates in this table refer to the availability of the recommended baseline IP list feature. **These are not enforcement dates.** Customers will receive a separate email notification when an enforcement date has been set for their specific instance.

  • Updated the link to find the stack location for a Marketing Cloud Engagement account

  • Updated the “Who’s affected” section to clarify the customers with IP allowlisting not enabled or set to monitoring-only mode at the enterprise or business unit level.

July 31, 2026

Removed the recommendation to contact Salesforce Support for adding over 50 IP ranges, as adding them directly by an Administrator is the fastest method. If your tenant currently has no Administrator, please contact your Account Representative to request one (takes a few business days).

July 21, 2026

Updated with Baseline IP list Release Group Schedule table

June 16, 2026

Initial publication

 

Knowledge-artikelnummer

005387198

 
Laddar
Salesforce Help | Article