🔍 You can now filter content to find what interests you! Log in to use the filters. New here? Register and finish setting up your account to get started.

background shape
background shape

Salesforce Enforces IP Allowlisting in Marketing Cloud on Sept 23

Salesforce began enforcing blocking-mode IP allowlisting for affected Marketing Cloud Engagement accounts on September 23, 2026, restricting both UI logins and API access to approved IP ranges. The change applies to accounts that were not already using the login IP allowlist in enforcement mode. (trailhead.salesforce.com)

Salesforce applies blocking mode at the enterprise level

The same-day Salesforce security notice says Salesforce is enabling `Log Violations and Deny Access` on behalf of affected customers. The setting is applied at the enterprise ID level, with the approved ranges used across the account’s Business Units. Existing IP ranges remain in place, while Salesforce adds a recommended baseline where required. (trailhead.salesforce.com)

The baseline is built from successful authentication activity observed during the previous six months and excludes known malicious IP addresses. Salesforce describes the ranges as standard `/24` networks, equivalent to 256 addresses per range. Accounts already using blocking mode are not changed by this enforcement step. (trailhead.salesforce.com)

Remote access and API integrations must use approved IPs

Once blocking mode is active, users can log in only from an address included on the Marketing Cloud Engagement allowlist. API requests are also subject to the same control, so integrations running from cloud infrastructure, middleware, VPNs, or changing residential connections can fail if their public egress address is missing. The Marketing Cloud Engagement allowlisting documentation confirms that the control covers both UI Login and API access. (help.salesforce.com)

Salesforce says customers are responsible for maintaining the allowlist after enforcement. Administrators should review the access logs for legitimate denied addresses and add stable egress ranges for users and integrations that still need access. A corporate VPN, dedicated egress proxy, static cloud IP, or centralized NAT gateway provides a more manageable source address than maintaining a large list of changing user IPs. (trailhead.salesforce.com)

Oh hi there 👋
I have a SSJS skill for you.

Sign up now to get an SSJS skill that can be used with your AI companion

We don’t spam! Read our privacy policy for more info.

Share With Others

The Author
Marcel Szimonisz Platinum

Marcel Szimonisz

MarTech consultant

I specialize in solving problems, automating processes, and driving innovation through major marketing automation platforms, particularly Salesforce Marketing Cloud and Adobe Campaign.

Your email address will not be published. Required fields are marked *

Subscribe

Get exclusive tips, scripts and news

Choose your topics

We don’t spam! Read our privacy policy for more info.

Similar posts
[mautic type='focus' id='1']