Salesforce is implementing a continuous authentication model for Marketing Cloud Engagement. This framework requires fresh identity verification before users can execute sensitive administrative tasks. This ensures that high-impact operations are protected by current, verified identity.
Salesforce is implementing a step-up verification framework. Users will be prompted for re-verification when attempting high-risk operations. Refer Step-Up Authentication.
Following successful verification, a user is granted a 30-minute validity window to execute any protected administrative operations. If a user initiates an edit or remains in edit mode beyond this 30-minute window, they will encounter a secondary authentication challenge upon attempting to save their changes.
The July 30, 2026 release will enable step-up verification for changes made on the Setup > Settings > Security Settings page. Additional sensitive operations will be added in future releases
This change aligns with Salesforce policy of protecting high-impact security operations from stale-session abuse and unauthorized access.
The enforcement starts July 30, 2026 staggered over 5 days.
To determine the specific start and end dates for your org, take these steps.
Identify your Salesforce instance. See View Instance Information for Your Salesforce Organization.
In the Release Group Instance Mapping table located below, find the release group for your instance.
Find the enforcement dates for your release group in the Release Group Enforcement Schedule below.
|
Release Group |
Start Date |
End Date |
|
R0 |
July 30, 2026 |
July 30, 2026 |
|
R1 |
August 3, 2026 |
August 3, 2026 |
|
R2a |
August 4, 2026 |
August 4, 2026 |
|
R2b |
August 5, 2026 |
August 5, 2026 |
|
All others not listed |
August 4, 2026 |
August 4, 2026 |
All admin users performing sensitive administrative operations in Marketing Cloud Engagement, including those using direct logins. Administrator roles include:
Marketing Cloud Administrator
Marketing Cloud Security Administrator
Email Studio Administrator
Or
Every user with permissions that include - Administration | Account | Update Account and Security Settings. Refer Permissions for Setting Up Marketing Cloud Engagement
At present, this enforcement does not affect SSO users.
Users will encounter a secondary authentication challenge when accessing sensitive features. If verification is successful, a temporary validity window is established for the session. If verification cannot be completed, the sensitive operation will be blocked.
Account administrators are provided with consolidated audit records and system-wide visibility into every verification instance. Use these tools to evaluate the current enrollment status for multi-factor authentication among your users. Refer Review MFA Enrollment Status for Marketing Cloud Engagement.
Additionally, a detailed history of registration and re-verification events is available for audit. Refer View MFA Events in Marketing Cloud Engagement
Is this the same as my initial login?
No, this is a "Step-Up" verification that occurs within your existing session.
Does this affect SSO users?
No. Step-up Authentication for SSO users will be enforced at a later date
Are there alternate security measures that can be configured that would skip the Step-up challenges (e.g. Trusted IP Ranges?
No, there is no compensating control to bypass step-up verification.
Q: What are the WebAuthn-Platform authenticators?
A: These authenticators are built directly into the device you are using. Eg. Apple Touch ID / Face ID, Windows Hello, Android fingerprint scanners.
Q: Is there a way for MCE administrators to check whether the target users in the organization have applied PR-MFA?
A: You can review the multi-factor authentication (MFA) enrollment status of users in your account. Refer Review MFA Enrollment Status for Marketing Cloud Engagement
Q: Will the audit log include information that allows us to confirm whether access was made via PR-MFA?
A: You can review a log of all multi-factor authentication (MFA) registration and verification attempts for your account. Refer View MFA Events in Marketing Cloud Engagement
Note: Release Group mapping is subject to change.
To learn how to identify your instance, see View Instance Information for Your Salesforce Organization.
Once you have determined the release group for your instance, find your detailed rollout timeline in the Release Group Enforcement Schedule mentioned above.
|
Release Group |
1P Instance |
Hyperforce Instance |
|
R0 |
S8 | |
|
R1 |
S4, S50 |
401, 406 |
|
R2a |
S11, S12, S13 |
402, 403 |
|
R2b |
S1, S5, S6, S7, 10, S51 |
|
Date |
Change |
| August 11, 2026 |
|
| July 20, 2026 | Initial publication |
005389128

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.