Salesforce enforces default report‑export Transaction Security Policy on July 13, 2026
Salesforce began enforcing a default Transaction Security Policy (TSP) on ReportEvent in production on July 13, 2026, automatically gating large report exports for orgs that haven’t configured their own policy, as listed in Sage People’s Salesforce updates schedule.
Salesforce enforces default Transaction Security Policy on ReportEvent
If an eligible org has no report‑export policy in place, Salesforce will auto‑create and enable a default rule that triggers on large exports. Arkus details that the out‑of‑the‑box control fires on report exports exceeding 10,000 records and went live for production orgs with the July 13 cutover in its five security changes coming in June 2026 note.
Impact for Salesforce Shield and Event Monitoring customers exporting reports
This enforcement targets customers with Shield or the Event Monitoring add‑on, because ReportEvent policies watch when report data is viewed or downloaded. Salesforce’s help content explains how ReportEvent policies monitor report access and export activity, which is why recurring CSV dumps, analyst self‑service exports, and some BI connector pulls are in scope.
Large report exports face step‑up authentication or blocks
In parallel with the enforcement window, Salesforce narrowed its report security to focus step‑up MFA challenges on the export action and shipped fixes to reduce workflow friction, as outlined in the company’s updates to Step‑Up Authentication for reports and dashboards. In practice, that means legitimate users may see an MFA challenge on export, and anomalous or oversized pulls can be blocked when the policy dictates.
Why this enforcement matters for data loss prevention
The default TSP raises a baseline against bulk data exfiltration from CRM reports. For data teams that rely on high‑volume exports, the immediate implication is operational: align thresholds and actions with how your business actually works to avoid unexpected blocks, and validate scheduled jobs that read from the Reports API. For admins, the control improves auditability around who moved large datasets out of Salesforce, when, and from where-without waiting for a custom policy to be built.
Verification of the July 13 production enforcement
Sage People’s change log shows “Transaction Security Policy (TSP) enhancement” enforced in Production starting 13 July, 2026, and Arkus independently confirms the default rule and July 13 production timing in its customer advisory. If you need to build or tune your own policy, Salesforce’s Trailhead module on creating Transaction Security Policies walks through setting conditions and actions so large, legitimate exports can be challenged instead of blocked outright.




