<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1333676407485327&amp;ev=PageView&amp;noscript=1">
Skip to content

Salesforce Report Step-Up Authentication: 2026 Admin Guide

Salesforce authentication changes

Starting mid-2026, Salesforce is adding two separate layers of step-up authentication around reports. One re-checks your identity after a session has been open for a while. The other, powered by machine learning, flags report exports that don't match your normal behavior—even minutes after you've already logged in with MFA. Here's how each control works, when it hits your org, and how to prepare your team so a re-authentication prompt doesn't look like a bug.

What's Happening: Two Related but Different Controls

Salesforce is rolling out step-up authentication in two distinct ways, and understanding the difference is critical for preparing your team.

Control A: Time-Based Session-Level Policy for Report Activities

After a session has been open for a set window, the next report action requires the user to step up and re-verify before continuing. This is predictable and time-driven.

Control B: Step-Up Authentication for Anomalous Report Export Behavior

An ML model learns each user's normal reporting patterns and triggers a step-up challenge the moment a report action deviates from that pattern—regardless of session age. This is behavior-driven and can happen even if someone just logged in.

Why This Matters

Report exports are a common attack vector. Once an attacker compromises a user account, one of the first things they do is export sensitive data—customer lists, financial records, employee information. By adding friction specifically around report actions, Salesforce is making that attack path harder without slowing down normal business operations.

This is part of a broader security trend at Salesforce. Over the past year, they've rolled out phishing-resistant MFA for admins, expanded MFA requirements, and added anomaly detection in multiple areas. Step-up authentication for reports is the next logical step.

Control A: Step-Up Auth for Report Activities (Time-Based Session Policy)

This is the more straightforward of the two controls. It's about session age, not behavior, so it's easier to explain to end users ahead of time.

What Triggers It

The session has been active past its allowed window. The next report action—whether running, viewing, or exporting a report—prompts re-authentication. The user completes the step-up challenge and can continue.

How It Works in Practice

A user logs in at 9 AM with MFA. They work normally throughout the morning. At 2 PM, they try to run a report they run every day. If their session window has expired, they'll see a step-up authentication prompt. They re-verify, and the report runs. It's similar to how some banking apps ask you to re-verify before transferring money.

Rollout Timeline

Sandboxes:

  • Available: May 27, 2026 (opt-in availability window, approximately 7 days)
  • Enforced: June 17, 2026 (approximately 7 days)

Production:

  • Available: May 27, 2026 (opt-in availability window, approximately 15 days)
  • Enforced: July 1, 2026 (approximately 30 days)

This staggered rollout gives you time to test in sandbox before it hits production.

Control B: Step-Up Auth for Anomalous Report Export Behavior

This is the more sophisticated control, and it's also the one that will surprise users most because it's not time-based — it's behavior-based.

What Triggers It

A machine-learning model tracks which reports a user runs, when they run them, how often, how many records they export, and whether they export at all. When the model detects a meaningful deviation from that pattern, it triggers a step-up challenge.

Examples of anomalous behavior that might trigger this:

  • A user who normally runs one report per week suddenly runs 50 reports in an hour
  • A user who never exports data suddenly exports 100,000 records
  • A user who typically runs reports during business hours suddenly runs reports at 3 AM
  • A user who normally accesses reports from their office suddenly accesses them from a different geographic location

Key Nuance: Behavior Trumps Session Age

Here's the critical distinction: this control can trigger even if the user is well within their normal session window and recently completed step-up authentication. It's not about how long they've been logged in. It's about what they're doing.

This means a user could log in at 9 AM, complete MFA, work normally until 10 AM, and then try to export a report in an unusual way and get challenged again. This is intentional. Salesforce is prioritizing the detection of compromised accounts over session convenience.

Rollout Timeline

Sandboxes:

  • Enforced: June 22, 2026

Production:

  • Enforced: July 13, 2026

Note that this control doesn't have an "available" phase—it goes straight to enforcement. This is because it's ML-based and requires a learning period. Salesforce will be collecting baseline behavior data before enforcement kicks in.

Key Dates at a Glance

Control

Environment

Available

Enforced

Report Activities (time-based)

Sandbox

May 27, 2026

June 17, 2026

Report Activities (time-based)

Production

May 27, 2026

July 1, 2026

Anomalous Export Behavior (ML)

Sandbox

June 22, 2026

Anomalous Export Behavior (ML)

Production

July 13, 2026

Why This Matters Even If "Nothing Looks Different" Day to Day

Most users won't notice anything until they hit a trigger. And that's the problem. The first time someone sees a step-up authentication prompt in the middle of their normal workflow, it can look like an error rather than a security feature.

Without proper communication, you'll get support tickets. Users will think something is broken. They might try to work around it. Or worse, they might assume their account has been compromised.

Preparing Your Team: Communication and Testing

Phase 1: Test in Sandbox (May 27 – June 17)

As soon as the controls become available in sandbox, enable them and test with your team. Have different users run reports in different ways. Try exporting large datasets. Try accessing reports from different locations or times of day. Document what triggers the step-up challenge and what doesn't.

This testing phase is critical because it lets you understand the ML model's baseline before it goes live in production.

Phase 2: Communicate the Change (Before July 1)

Send a message to your team explaining what's happening. Use language like:

"Starting July 1, Salesforce is adding extra security checks around reports. If you see a prompt asking you to re-verify your identity while running or exporting a report, that's normal. It's a security feature, not an error. Just complete the verification and you can continue."

Include examples of what might trigger the prompt. Explain that it's designed to protect sensitive data.

Phase 3: Monitor and Adjust (After July 1)

After enforcement goes live, monitor your support tickets and user feedback. If certain report actions are triggering challenges more often than expected, you may need to adjust your communication or workflow.

For example, if your finance team exports large datasets every month and the ML model flags this as anomalous, you might need to whitelist that behavior or adjust the model's sensitivity.

Who This Affects

Everyone with report access will be affected by Control A (time-based session policy). If you run or export reports, you might see a step-up challenge.

Users with unusual reporting patterns will be most affected by Control B (anomalous behavior detection). This includes:

  • Admins who run reports across multiple departments
  • Finance teams that export large datasets
  • Consultants or contractors who access reports outside normal business hours
  • Users who access reports from different locations

Shield customers may have additional controls or customization options around these policies. If you're a Shield customer, check with your Salesforce consulting partner about any org-specific configurations.

The Bigger Picture: Why Salesforce Is Doing This

Report exports are a common attack vector. Once an attacker compromises a user account, one of the first things they do is export sensitive data — customer lists, financial records, employee information. By adding friction specifically around report actions, Salesforce is making that attack path harder without slowing down normal business operations.

This is part of a broader security trend at Salesforce. Over the past year, they've rolled out phishing-resistant MFA for admins, expanded MFA requirements, and added anomaly detection in multiple areas. Step-up authentication for reports is the next logical step.

Frequently Asked Questions

What is step-up authentication in Salesforce?

Step-up authentication is an extra identity check Salesforce prompts for before a sensitive action, even when the user is already logged in with MFA. For reports in 2026, it means a user may be asked to re-verify before running, viewing, or exporting a report, then can continue as normal.

Why is Salesforce asking me to re-authenticate when I run a report?

Two controls can trigger it. A time-based session policy prompts re-verification once a session has been open past its allowed window. A separate machine-learning control prompts when a report action deviates from your normal pattern, such as exporting far more records than usual or running reports at an unusual time. It is a security feature, not an error.

What is the difference between the time-based and behavior-based report controls?

The time-based control (Control A) is driven by session age: after your session passes its window, the next report action requires a step-up challenge. The behavior-based control (Control B) is driven by an ML model that watches your reporting patterns and can challenge you at any time, even minutes after you logged in, if an action looks anomalous.

When does Salesforce report step-up authentication take effect?

The time-based session policy is available May 27, 2026 in both Sandbox and Production, enforced June 17, 2026 in Sandbox and July 1, 2026 in Production. The ML-based anomalous export control goes straight to enforcement: June 22, 2026 in Sandbox and July 13, 2026 in Production.

Can behavior-based step-up trigger even if I just logged in?

Yes. The ML control is not tied to session age. A user can log in, complete MFA, work normally, and still be challenged when a report action deviates from their baseline. This is intentional so Salesforce can catch compromised accounts rather than rely on session convenience.

How should admins prepare for report step-up authentication?

Enable and test the time-based policy in a sandbox from May 27 to understand what triggers a challenge, then communicate the change to your team before July 1 production enforcement so a prompt is not mistaken for a bug. After enforcement, monitor support tickets and adjust communication or workflows for teams with heavy or unusual reporting, such as finance exports.

Schema note: The questions and answers above are mirrored exactly in the FAQPage JSON-LD at the end of this document. If you edit a question or answer here, update the matching entry in the schema so the two stay in sync.

Moving Forward

Step-up authentication for reports is one of several security changes Salesforce is rolling out in 2026. If you're managing a complex Salesforce environment, staying ahead of these changes requires planning and communication. For organizations looking to implement these controls smoothly, consider working with experienced Salesforce consulting partners who can help you test, communicate, and optimize your security posture.

The key is to treat this not as a disruption, but as an opportunity to strengthen your security while educating your team about why these controls matter. Understanding how sales activity tracking and territory management work in Salesforce will also help you appreciate the broader security context. Contact us today if you want to discuss how to prepare your org for these changes.

Partner With Concept

Share your details and our team will reach out to discuss collaboration opportunities