Salesforce turns on step-up authentication for Marketing Cloud Security Settings on July 30, 2026
Salesforce activated step-up authentication for Security Settings changes in Marketing Cloud Engagement on July 30, 2026, and is rolling it out by release group over the next few days. The control forces an extra identity check before admins can save updates on the Security Settings page, tightening protection on high‑impact actions that attackers commonly target.
Marketing Cloud Engagement adds step-up authentication on Security Settings starting July 30, 2026
Per Salesforce Help, the new requirement applies to any change made under Setup → Settings → Security Settings in Marketing Cloud Engagement. The policy went live for the first release group on July 30, with additional waves scheduled in early August; Salesforce notes there is no compensating control to bypass these prompts, including trusted IP ranges, and SSO users will have specific enforcement timing communicated separately. Details are outlined in the Step‑Up Authentication in Marketing Cloud Engagement guidance, including exactly where re‑verification now appears and what admins should expect during the prompt flow (Salesforce Help: Step‑Up Authentication in Marketing Cloud Engagement).
Release group schedule and enforcement window for admins
Salesforce is delivering the change by release group rather than all at once. The Help article lists R0 on July 30, followed by R1 on August 3, R2a on August 4, and R2b on August 5, with a one‑day window for each group. In practice, that means different business units may see the step‑up prompt on different days if they operate multiple Marketing Cloud instances. If you are unsure which group you’re in, the instructions for finding your instance and matching it to the schedule are included in the same Help resource (release group mapping and dates).
Why Salesforce is tightening access to high‑risk actions
This change is part of a broader 2026 security program that adds step‑up authentication to sensitive surfaces across Salesforce. The platform’s security update tracker defines step‑up authentication as an extra identity check for actions that could expose or move data, and it documents the July schedule adjustments for MFA and other step‑up rules after Salesforce paused and then resumed enforcement earlier in the month. That context explains why Marketing Cloud’s Security Settings are now gated-Salesforce is standardizing higher assurance for administrative operations across products (Security‑Related Product Updates overview).
Immediate implications for Marketing Cloud teams
- Expect prompts during admin work: Any save on the Security Settings page can trigger a re‑verification challenge. In larger teams, this often surfaces first in maintenance windows when updating domains, certificates, or export controls.
- Plan for staggered timing: If you manage multiple orgs or instances, track when each release group enforces the change so maintenance does not stall mid‑update.
- No bypass via network rules: Trusted IPs and similar controls won’t skip the step‑up prompt. Ensure admins have access to their second factor wherever they perform work.
- Coordinate with SSO teams: Enforcement for federated users may run on a separate timetable; align Identity and Security owners now so challenges resolve cleanly in SSO flows (Security‑Related Product Updates).
Related context: report exports already require step‑up this month
While the new enforcement targets Marketing Cloud Security Settings specifically, Salesforce also began enforcing step‑up for report export and selected report actions in core Salesforce earlier in July. If your admins saw new prompts there, the behavior in Marketing Cloud will feel familiar, but the triggers are different and product‑specific (Prepare for step‑up on report actions).





