*** Important Update: Step-Up Authentication for Report Actions ***Hey Trailblazers! We have some important updates to share about the upcoming Step-Up Authentication requirement for Report Actions — Here's what you need to know:
Change 1: Step-Up Challenges Now Scoped to Export Actions Only
Step-Up Authentication challenges will now trigger only when exporting or printing reports — not when simply viewing reports, dashboards, or accessing the Reports/Dashboards tabs in the UI.
The Session Level Policy setting has been added to reflect this:
"Require periodic step-up authentication when exporting or printing"
This updated policy replaces the prior setting upon enforcement. Find this by going to Setup -> Identity Verification and selecting the new policy for Reports and Dashboards.
Change 2: Profile Login IP Restrictions as an Alternate Control
Step-Up Authentication for report exports will not be required when both of the following conditions are met:
- A user's Profile has Login IP restrictions configured, AND
- Either the user's IP address hasn't changed between login and report export, or "Enforce login IP ranges on every request" is enabled in Session Settings
This gives admins a meaningful alternate control if your org uses IP-based access restrictions and when configured, users will not see step-up challenges during report export.
Enforcement Timeline — No Changes
Enforcement dates remain unchanged from what was previously published:
- All Sandboxes: June 17 – June 24
- Production: July 1 – July 25
Additional Resources
- Prepare for the upcoming Step-Up Authentication requirements on Report Actions (Updated June 16, 2026)
- Restrict Login IP Addresses in Profiles
Have questions? Drop them in the comments below — we're here to help!
thanks for this information: "...in our testing, we have OKTA authentication for login but I currently have Salesforce authenticator as well so it kicks me there to verify the export."
I was
wondering whether Admins could respond to the report export challenges via the regular authenticator. To me, that seems easier than going back to the initial login method for Admins, which in our case might be Entra with a biometric option. Is this what others are seeing? (thanks, this has been very confusing for our small-ish org)