
Why Your Team Might Get Stopped Mid-Report in Salesforce — And What to Tell Them
Your sales team runs reports every day. Pipeline reviews, activity summaries, deal forecasts. It’s routine. So when Salesforce stops someone mid-report and asks them to verify their identity before they can see their data, the first assumption is going to be that something is broken.
It’s not broken. It’s a new security feature called step-up authentication, and it’s being enforced this summer whether your team is ready for it or not.
What Step-Up Authentication Is
Step-up authentication is an additional verification layer that Salesforce is adding on top of the standard login process. Even after a user has already logged in to Salesforce using MFA, the system can now require them to verify their identity again when it detects certain activity — specifically around running and viewing reports.
The trigger is what Salesforce describes as significant deviations in user activity. What that means exactly isn’t precisely defined, but the intent is clear: Salesforce is watching for behavior that looks unusual around report access, particularly anything that suggests data might be getting exported in bulk or by someone who shouldn’t have access to it.
When the system flags something, the user gets prompted to re-authenticate before the report loads. They verify using whichever MFA method they have set up, and then they’re back in. The interruption is brief, but it can be jarring if no one told them it was coming.
Why Salesforce Is Doing This Now
Reports are one of the most significant data exposure points in any Salesforce environment. They can surface large volumes of sensitive business data — customer records, deal values, contact information — and they can be exported with a few clicks. As Salesforce expands its AI capabilities and more tools gain the ability to interact with platform data, tightening controls around report access is a logical step.
This is part of a broader security push across the Summer ’26 release. Salesforce is also adding AI-driven anomaly detection that can flag unusual behavior patterns and trigger re-authentication automatically. If a user who has never exported a report suddenly tries to pull 50,000 records, the system is going to notice.
The goal isn’t to make reporting harder. It’s to make sure the right people are accessing the right data, and that access is verified at the point it matters most.
How It Works in Practice
The re-authentication window is configurable, somewhere between two minutes and two hours depending on how your environment is set up. That means a user who verifies their identity at 9 a.m. may not be prompted again until later in the morning, depending on the setting and their activity.
For users who run reports frequently throughout the day, this may become a regular part of their workflow. For users who only pull a report occasionally, it may feel more disruptive when it does happen.
The re-authentication itself is the same process as their normal MFA step. They’ll confirm their identity using their authenticator app, their fingerprint reader, or whichever method they have configured. Once verified, they can access the report and continue working.
Report subscriptions — scheduled reports that are automatically delivered to a user’s inbox — are not affected by this change. The step-up authentication applies to users who are actively logging in and running or viewing reports, not to automated delivery.
What to Tell Your Team Before It Happens
The most effective thing a business leader can do right now is get ahead of this with a simple heads-up. Your team doesn’t need a detailed technical explanation. They need to know three things.
First, Salesforce may ask them to verify their identity again when they try to run a report, even though they already logged in. Second, this is not a glitch or a sign that something is wrong with the system. Third, they should complete the verification the same way they do when they first log in, and they’ll be back in their report immediately.
That’s it. A two-minute conversation or a quick message to your team before this starts happening will eliminate most of the confusion and support requests that would otherwise follow.
What to Watch for as This Rolls Out
The enforcement timeline for step-up authentication moved quickly. Sandboxes were first, with production following shortly after. By the time this episode aired, it was already in effect or very close to it in most environments.
If your team has already started seeing these prompts, that’s expected. If you’re hearing complaints that Salesforce is asking people to log in again in the middle of their work, this is why. Walk them through what’s happening and confirm their MFA method is set up correctly so the verification process is as smooth as possible.
If users are getting stuck — if the re-authentication step isn’t working or they’re not set up with the right method — that’s worth escalating to your Salesforce administrator. The issue usually comes down to MFA not being properly configured in the first place, which brings everything back to the broader enforcement changes happening across this release.
Listen to the full podcast episode here.