✏️ Now anyone can publish articles, collect points, and earn badges. Get 6 months of Premium access for your first approved article. Register to start your journey.

background shape
background shape

Salesforce starts step-up authentication in Marketing Cloud Engagement on August 3, 2026 for R1 orgs

Salesforce is enforcing step-up authentication for high‑impact settings in Marketing Cloud Engagement on August 3, 2026, for customers in the R1 release group, requiring fresh identity verification before administrators can change core security controls.

Marketing Cloud Engagement step-up authentication begins August 3, 2026

Salesforce’s rollout makes “continuous authentication” mandatory for sensitive administration in Marketing Cloud Engagement. According to the official guidance, step-up prompts now appear when an admin changes items under Settings – Security Settings, with additional protected operations to be added over time. The R1 enforcement date is August 3, 2026, following an initial R0 wave on July 30 and additional waves on August 4 and 5. Details, including the operation scope and schedule by release group, are listed in Salesforce’s Step‑Up Authentication in Marketing Cloud Engagement article.

Which Salesforce orgs are in the August 3 (R1) window

Salesforce maps enforcement windows to specific instances. In the same rollout guidance, R1 includes 1P instances S4 and S50 and Hyperforce instances 401 and 406, which receive enforcement on August 3, 2026. Customers can confirm their instance and release group in the mapping table linked from the Marketing Cloud Engagement article above. Salesforce also maintains a platform‑level security rollup that tracks related policies and dates; it confirms step‑up requirements expanding across the core platform, with production enforcement windows running through July and into early August for select features, as outlined in Security‑Related Product Updates to the Salesforce Platform.

What changes for administrators in Marketing Cloud Engagement

In practice, admins will see a secondary verification challenge when attempting high‑impact actions, such as changing allowlists, certificate settings, or data export configurations. Salesforce states that step‑up is designed to block stale or hijacked sessions from performing sensitive work; there’s no compensating control to bypass these checks in Marketing Cloud Engagement. The enforcement covers direct logins first; step‑up for federated SSO flows will be enforced later per Salesforce’s Marketing Cloud Engagement step‑up guidance.

Immediate actions to avoid lockouts on August 3

  • Verify that all administrators who manage MCE security have an active identity verification method configured and working in their current login flow.
  • Review who can access Settings – Security Settings and adjacent high‑impact areas; least‑privilege profiles will reduce the number of users encountering step‑up prompts during urgent changes.
  • Communicate the new workflow to on‑call and release teams so they expect a verification challenge during changes made during maintenance windows.

How this aligns with platform report-export protections

Separately from MCE, Salesforce has been enforcing step‑up checks around report and dashboard access and export within the core platform, including a session‑level policy that, after enforcement, limits periodic step‑up to export and print actions. Platform enforcement timelines and policy behavior are documented in Prepare for the upcoming Step‑up Authentication requirements on Report Actions. While this is a distinct control path from MCE, teams that manage both Sales/Service Clouds and Marketing Cloud Engagement should plan for consistent user messaging and support.

Why this matters for security and operations

Step‑up authentication materially reduces the blast radius of compromised or idle sessions by forcing fresh verification at the point of high‑impact change. For MCE customers with strict change‑control processes, the operational impact is minimal if users are briefed and prepared; for ad‑hoc changes made under time pressure, the extra challenge adds seconds but provides a measurable layer of protection at exactly the right moment. The enforcement beginning on August 3, 2026 for R1 instances brings MCE one step closer to parity with the platform‑wide controls Salesforce has been rolling out across report export and other sensitive actions, as reflected in the platform security update tracker and the MCE rollout notice.

Oh hi there 👋
I have a SSJS skill for you.

Sign up now to get an SSJS skill that can be used with your AI companion

We don’t spam! Read our privacy policy for more info.

Share With Others

The Author
Marcel Szimonisz Platinum

Marcel Szimonisz

MarTech consultant

I specialize in solving problems, automating processes, and driving innovation through major marketing automation platforms, particularly Salesforce Marketing Cloud and Adobe Campaign.

Your email address will not be published. Required fields are marked *

Buy me a coffee
Subscribe

Get exclusive tips, scripts and news

Choose your topics

We don’t spam! Read our privacy policy for more info.

Similar posts