Salesforce has completed the first phase of a Marketing Cloud Engagement security update that requires administrators to perform a fresh identity check before changing specified high-risk settings.
The rollout began July 30 and reached its final group of production environments on August 5. The initial enforcement applies when a directly signed-in user attempts to modify options under Setup, Settings and Security Settings. Salesforce says federated single sign-on users will be brought under the requirement in a later phase.
The check is separate from the authentication that opened the user’s session. When an administrator reaches a protected operation, Marketing Cloud Engagement asks for an approved Salesforce multi-factor authentication method. A successful check creates a temporary validity window, so the user does not have to repeat the process for every immediate action. A failed check blocks the change.
Trusted IP ranges do not bypass the requirement. That design is intended to reduce the value of a hijacked session or a compromised administrator account, including cases in which an attacker is already operating from an approved network.
Salesforce plans to extend the control to database encryption, MFA configuration, login IP allowlists, export email allowlists, domain allowlists, SSL certificates and data-export operations. The company also plans future support for platform authenticators such as Touch ID, Windows Hello and passkeys. Those authenticators are not part of the current release.
Salesforce is applying reauthentication at the moment an administrator attempts a sensitive change. Vercel recently put internal applications behind corporate identity-provider policies, while Salesforce’s model adds another verification point at the moment an administrator attempts a sensitive change.
Marketing Cloud Engagement records the step-up events in centralized audit logs. That gives security teams a record of whether a protected action triggered verification and whether the user completed it, supporting incident review and compliance reporting.
Salesforce has already used step-up authentication elsewhere in its platform, including for sensitive reports and dashboards. The company says that control is designed to balance access to business data with the risk of session theft. The Marketing Cloud rollout applies the same principle to configuration changes that could weaken security or expose customer information.
Salesforce has also served as a distribution channel for identity-verification tools, including Onfido integration with Financial Services Cloud. The latest update addresses the platform’s own administrator assurance rather than customer onboarding.
Sources: Salesforce Help, Salesforce
–
By the ID Tech Editorial Team






Follow Us