✏️ Now anyone can publish articles, collect points, and earn badges. Get 6 months of Premium access for your first approved article. Register to start your journey.

background shape
background shape

Salesforce enforces default report‑export Transaction Security Policy on July 13, 2026

Salesforce began enforcing a default Transaction Security Policy (TSP) on ReportEvent in production on July 13, 2026, automatically gating large report exports for orgs that haven’t configured their own policy, as listed in Sage People’s Salesforce updates schedule.

Salesforce enforces default Transaction Security Policy on ReportEvent

If an eligible org has no report‑export policy in place, Salesforce will auto‑create and enable a default rule that triggers on large exports. Arkus details that the out‑of‑the‑box control fires on report exports exceeding 10,000 records and went live for production orgs with the July 13 cutover in its five security changes coming in June 2026 note.

Impact for Salesforce Shield and Event Monitoring customers exporting reports

This enforcement targets customers with Shield or the Event Monitoring add‑on, because ReportEvent policies watch when report data is viewed or downloaded. Salesforce’s help content explains how ReportEvent policies monitor report access and export activity, which is why recurring CSV dumps, analyst self‑service exports, and some BI connector pulls are in scope.

Large report exports face step‑up authentication or blocks

In parallel with the enforcement window, Salesforce narrowed its report security to focus step‑up MFA challenges on the export action and shipped fixes to reduce workflow friction, as outlined in the company’s updates to Step‑Up Authentication for reports and dashboards. In practice, that means legitimate users may see an MFA challenge on export, and anomalous or oversized pulls can be blocked when the policy dictates.

Why this enforcement matters for data loss prevention

The default TSP raises a baseline against bulk data exfiltration from CRM reports. For data teams that rely on high‑volume exports, the immediate implication is operational: align thresholds and actions with how your business actually works to avoid unexpected blocks, and validate scheduled jobs that read from the Reports API. For admins, the control improves auditability around who moved large datasets out of Salesforce, when, and from where-without waiting for a custom policy to be built.

Verification of the July 13 production enforcement

Sage People’s change log shows “Transaction Security Policy (TSP) enhancement” enforced in Production starting 13 July, 2026, and Arkus independently confirms the default rule and July 13 production timing in its customer advisory. If you need to build or tune your own policy, Salesforce’s Trailhead module on creating Transaction Security Policies walks through setting conditions and actions so large, legitimate exports can be challenged instead of blocked outright.

Oh hi there 👋
I have a SSJS skill for you.

Sign up now to get an SSJS skill that can be used with your AI companion

We don’t spam! Read our privacy policy for more info.

Share With Others

The Author
Marcel Szimonisz Platinum

Marcel Szimonisz

MarTech consultant

I specialize in solving problems, automating processes, and driving innovation through major marketing automation platforms, particularly Salesforce Marketing Cloud and Adobe Campaign.

Your email address will not be published. Required fields are marked *

Buy me a coffee
Subscribe

Get exclusive tips, scripts and news

Choose your topics

We don’t spam! Read our privacy policy for more info.

Similar posts