Loading

Step-Up Authentication in Marketing Cloud Engagement

게시 일자: Jul 20, 2026
상세 설명

Salesforce is implementing a continuous authentication model for Marketing Cloud Engagement. This framework requires fresh identity verification before users can execute sensitive administrative tasks. This ensures that high-impact operations are protected by current, verified identity.

What’s Changing

Salesforce is implementing a step-up verification framework. Users will be prompted for re-verification when attempting high-risk operations. The July 30, 2026, release will enable step-up verification for any change on the Setup -> Settings -> Security Settings page. Additional sensitive operations will be added in future releases, including:

  • Database Encryption

  • Multi-Factor Authentication

  • Login IP Allowlist

  • Export Email Allowlist

  • Domain Allowlist

  • Domain SSL Certificates

  • Data Export

Why Is Salesforce Making This Change

This change aligns with Salesforce policy of protecting high-impact security operations from stale-session abuse and unauthorized access.

When Does This Change Take Effect

The enforcement starts July 30, 2026 staggered over 5 days.

Release Group Enforcement Schedule 

To determine the specific start and end dates for your org, take these steps.

  1. Identify your Salesforce instance. See View Instance Information for Your Salesforce Organization.

  2. In the Release Group Instance Mapping table located below, find the release group for your instance.

  3. Find the enforcement dates for your release group in the Release Group Enforcement Schedule below.

Release Group

Start Date

End Date

R0

July 30, 2026

July 30, 2026

R1

August 3, 2026

August 3, 2026

R2a

August 4, 2026

August 4, 2026

R2b

August 5, 2026

August 5, 2026

All others not listed

August 4, 2026

August 4, 2026

 

Who’s Affected

All users performing sensitive administrative operations in Marketing Cloud Engagement, including those using direct logins and federated SSO.

What to Expect

Users will encounter a secondary authentication challenge when accessing sensitive features. If verification is successful, a temporary validity window is established for the session. If verification cannot be completed, the sensitive operation will be blocked.

Before Enforcement: How to Prepare

  • Ensure all administrators are currently enrolled in a supported Salesforce MFA method. Note: Marketing Cloud Engagement will add support for platform authenticators (e.g., Touch ID, Windows Hello, or Passkeys) in an upcoming release.

  • SSO users should prepare for potential secondary verification requirements.

  • Administrators are recommended to start using the Phishing-Resistant MFA method early. While this can be skipped for now, recurring email reminders will be sent.

After Enforcement: Monitoring

Administrators will have access to centralized audit logs and operational monitoring for all verification events.

Common Questions

Is this the same as my initial login?
No, this is a "Step-Up" verification that occurs within your existing session.

Does this affect SSO users?
No. Step-up Authentication for SSO users will be enforced at a later date

Are there alternate security measures that can be configured that would skip the Step-up challenges (e.g. Trusted IP Ranges?
No, there is no compensating control to bypass step-up verification.

Release Group Instance Mapping

Note: Release Group mapping is subject to change.

To learn how to identify your instance, see View Instance Information for Your Salesforce Organization

Once you have determined the release group for your instance, find your detailed rollout timeline in the Release Group Enforcement Schedule mentioned above.

Release Group

1P Instance

Hyperforce Instance

R0

S8

R1

S4, S50

401, 406

R2a

S11, S12, S13

402, 403

R2b

S1, S5, S6, S7, 10, S51

 

솔루션

Change Log

Date

Change

July 20, 2026Initial publication

 

Knowledge 기사 번호

005389128

 
로드 중
Salesforce Help | Article