Salesforce is implementing a continuous authentication model for Marketing Cloud Engagement. This framework requires fresh identity verification before users can execute sensitive administrative tasks. This ensures that high-impact operations are protected by current, verified identity.
Salesforce is implementing a step-up verification framework. Users will be prompted for re-verification when attempting high-risk operations. The July 30, 2026, release will enable step-up verification for any change on the Setup -> Settings -> Security Settings page. Additional sensitive operations will be added in future releases, including:
Database Encryption
Multi-Factor Authentication
Login IP Allowlist
Export Email Allowlist
Domain Allowlist
Domain SSL Certificates
Data Export
This change aligns with Salesforce policy of protecting high-impact security operations from stale-session abuse and unauthorized access.
The enforcement starts July 30, 2026 staggered over 5 days.
To determine the specific start and end dates for your org, take these steps.
Identify your Salesforce instance. See View Instance Information for Your Salesforce Organization.
In the Release Group Instance Mapping table located below, find the release group for your instance.
Find the enforcement dates for your release group in the Release Group Enforcement Schedule below.
|
Release Group |
Start Date |
End Date |
|
R0 |
July 30, 2026 |
July 30, 2026 |
|
R1 |
August 3, 2026 |
August 3, 2026 |
|
R2a |
August 4, 2026 |
August 4, 2026 |
|
R2b |
August 5, 2026 |
August 5, 2026 |
|
All others not listed |
August 4, 2026 |
August 4, 2026 |
All users performing sensitive administrative operations in Marketing Cloud Engagement, including those using direct logins and federated SSO.
Users will encounter a secondary authentication challenge when accessing sensitive features. If verification is successful, a temporary validity window is established for the session. If verification cannot be completed, the sensitive operation will be blocked.
Ensure all administrators are currently enrolled in a supported Salesforce MFA method. Note: Marketing Cloud Engagement will add support for platform authenticators (e.g., Touch ID, Windows Hello, or Passkeys) in an upcoming release.
SSO users should prepare for potential secondary verification requirements.
Administrators are recommended to start using the Phishing-Resistant MFA method early. While this can be skipped for now, recurring email reminders will be sent.
Administrators will have access to centralized audit logs and operational monitoring for all verification events.
Is this the same as my initial login?
No, this is a "Step-Up" verification that occurs within your existing session.
Does this affect SSO users?
No. Step-up Authentication for SSO users will be enforced at a later date
Are there alternate security measures that can be configured that would skip the Step-up challenges (e.g. Trusted IP Ranges?
No, there is no compensating control to bypass step-up verification.
Note: Release Group mapping is subject to change.
To learn how to identify your instance, see View Instance Information for Your Salesforce Organization.
Once you have determined the release group for your instance, find your detailed rollout timeline in the Release Group Enforcement Schedule mentioned above.
|
Release Group |
1P Instance |
Hyperforce Instance |
|
R0 |
S8 | |
|
R1 |
S4, S50 |
401, 406 |
|
R2a |
S11, S12, S13 |
402, 403 |
|
R2b |
S1, S5, S6, S7, 10, S51 |
|
Date |
Change |
| July 20, 2026 | Initial publication |
005389128

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.