While the intent behind Salesforce’s step-up authentication framework is both understandable and necessary given the increasing sophistication of data exfiltration risks, the current implementation introduces meaningful friction into core user workflows—particularly around reports and dashboards, which are among the most frequently accessed features for our business teams.
From an adoption and usability standpoint, this experience is suboptimal. Requiring users to re-authenticate at the point of simply
viewing or runninga report—potentially multiple times per day—creates interruption in critical workflows, slows down data access, and adds cognitive and operational overhead. This is especially impactful in environments like ours where we are actively driving Salesforce adoption, encouraging teams to replace offline trackers, and reinforcing Salesforce as the single source of truth.
There is a real risk that this added friction could inadvertently push users back toward less secure, manual alternatives (e.g., screenshots, exported files stored locally, or shadow tracking), which ultimately undermines both the adoption goals and the spirit of the security control itself.
While the security objective is valid, the user experience could be significantly improved with more thoughtful enablement patterns and modern authentication approaches. Guidance that I would have assumed be offered by Salesforce themselves.
For example:
- Seamless, low-friction verification methods such as push-based approvals (e.g., Salesforce Authenticator prompts) should be the default and strongly encouraged over email/SMS OTP, which are slower and more disruptive.
- Biometric-based authentication (Face ID, Touch ID) and passkey/passwordless experiences should be positioned as the primary path to reduce user effort during step-up challenges.
- Clear guidance and best practices from Salesforce on how to configure session policies (e.g., optimal step-up intervals by role/use case) would help organizations strike the right balance between security and usability.
- Proactive end-user enablement (tooltips, in-product guidance, and admin playbooks) would ensure users understand why the prompt is happening and how to complete it quickly.
Ultimately, achieving the right balance between security and usability
is critical. If step-up authentication becomes too intrusive, it risks becoming a barrier to productivity and platform adoption—particularly for high-frequency report users.
A more user-centric approach—leveraging modern, fast, and intuitive authentication methods combined with stronger guidance for Salesforce—would help ensure this change enhances security
without compromising the momentum on we're making on adoption and workflow efficiency.
Any suggestions?
#MFA #Security