TrueSolv — Header Component
Home >> News >> Salesforce Report Step-Up MFA

Salesforce Report Step-Up MFA

Salesforce report step-up MFA verification prompt and admin interval configuration setup path

Starting July 1, your Salesforce users will be prompted to verify their identity every time they open a report. Not when they export it. Every time they open it. Every 120 minutes by default. If nobody on your team knew this was coming, Monday morning answered that question with a support queue. Here is what it is, why Salesforce introduced it, and what admins need to configure — including the setting most documentation skips.

Reports → Q2 Customer Pipeline
Report content loading...
🔐
Verify your identity to view this report
Salesforce requires identity re-verification to access reports. This prompt appears every 120 minutes by default.
📱
Salesforce AuthenticatorTap the notification in the app
🔑
Security KeyInsert and touch your key
No enrolled method? You'll receive a one-time code by email or SMS instead.

What step-up MFA on reports actually means

Step-up MFA is a secondary verification that fires when a user reaches a high-risk surface, even if they already authenticated with MFA at login. In this case, the trigger is any Salesforce report — opening it, not exporting it. The prompt appears before the report loads.

The default re-verification window is 120 minutes. After a user verifies, they can open reports freely for 120 minutes before the prompt returns. This is configurable — which is the part most admin documentation understates.

For users already enrolled in an MFA method, the step takes 15 to 30 seconds. For users with no enrolled method, the system falls back to email or SMS one-time passcode. If that also fails, the user cannot open the report at all. This applies to all internal orgs platform-wide, live since July 1.

Why Salesforce introduced it

Reports are the highest-risk data surface in most Salesforce orgs. A user with View All Data can navigate to the Reports tab, open a standard contact report, run it unfiltered, and export 50,000 records to a spreadsheet in under two minutes. The exported file leaves Salesforce with no record that it happened unless a Transaction Security Policy was in place.

The step-up MFA requirement is specifically about the gap between "authenticated at login" and "accessing a surface that enables bulk data extraction." Login MFA proves identity when a session starts. Step-up MFA proves continued identity at the moment of high-risk data access.

What admins need to do now — four steps

Report Step-Up MFA — Admin ActionsLive July 1
1
Communicate to all report users before they discover it themselves
Without context, users interpret the verification prompt as a security incident, phishing attempt, or system error. A one-paragraph internal message — what the prompt is, why it appears, what to do if it fails, who to contact — prevents a wave of support tickets and builds trust rather than confusion.
2
Verify all active users have an enrolled MFA method
Setup → Identity → Identity Verification. Add MFA enrollment status column to your user list view. Users without any enrolled method fall back to email or SMS OTP. If that also fails — no mobile number registered, slow email delivery — they cannot open reports. Reach out to unenrolled users directly.
3
Configure the re-verification interval for your team's workflow
The 120-minute default is adjustable and most documentation skips this. Find it at: Setup → Identity → Session Settings → High-Assurance Session Timeout. The setting is org-wide. Consider shorter (60 min) for regulated environments; consider longer (240 min) for teams running reports continuously throughout the day.
4
Create a user FAQ covering the four questions that will recur
Answer proactively: what is this prompt, how to enroll an MFA method, what to do if verification fails, and whether the prompt means the account has been hacked. A Chatter post or internal knowledge article takes an hour and replaces dozens of individual support conversations.
Configuring the re-verification interval — where to find it
Setup → Identity → Session Settings → High-Assurance Session Timeout
60 min
Regulated environments — HIPAA, SOC 2, or internal policies requiring shorter session timeouts. More frequent prompts, stronger security posture. Appropriate if your audit requirements specify session limits.
120 min
Default — Salesforce's chosen balance between security and usability. Suitable for most orgs. Users in standard report workflows will see the prompt once or twice per working day.
240 min
High-frequency reporting teams — Analytics, operations, and management teams running reports throughout the day who find 120-minute prompts disruptive. One prompt at the start of the work session, one at the end.

What this does not affect

External users and Experience Cloud community users are not covered by the report step-up requirement in the current enforcement scope. The change applies to internal users accessing Salesforce through the standard internal login path.

Reports embedded in Lightning record page dashboards operate differently from reports accessed directly through the Reports tab. The step-up prompt fires when a user navigates directly to a report — not currently when a dashboard component rendering report data is loaded on a record page. This distinction matters for orgs where report data is primarily surfaced through embedded dashboard components rather than the Reports tab itself.

Step-up MFA on reports has been live since July 1. If your users have already encountered it, the communication gap already cost you some support tickets. The remaining configuration work — interval adjustment and the internal FAQ — takes less than a day and prevents the same tickets from recurring every time a new user hits the prompt for the first time.

Share:
Free Consultation

Ready to solve your Salesforce challenges?

Get a free consultation with our certified Salesforce experts. No commitment required.

See our packages →
TrueSolv — Footer Component