Do report integrations keep working after step-up authentication and MFA enforcement in Japan (Sept 1, 2026)?
According to Salesforce's official FAQ, step-up authentication applies only to interactive UI sessions. API access to reports (integrations, connected apps, programmatic retrieval) and scheduled report subscriptions are excluded[1]. The September 1 MFA enforcement covers UI login, and Salesforce states that integrations using the JWT bearer flow or client credentials flow are not affected[2]. However, a tool connected through the API can still be blocked if it fetches data through the same path as a UI export: users of Google's Salesforce Connector reported that report imports over 2,000 rows fail due to step-up authentication[3].
July step-up authentication and September MFA are separate changes
The extra check on every export comes from step-up authentication, not from the September MFA enforcement. Dates are for production orgs; sandboxes started earlier.
| When | Change | Who |
|---|---|---|
| Rolled out over ~30 days from July 1, 2026 | Step-up authentication (an extra MFA check) on report export. Admins set the re-check interval from 1 to 120 minutes[1] | Paid production and sandbox orgs |
| From July 27, 2026 | Step-up when unusual report activity is detected[4] | Same (currently mainly UI downloads) |
| September 1, 2026 (Japan and Korea) | MFA enforced on UI login for all employee users[2] | Paid production and sandbox orgs |
What the official FAQ excludes
The FAQ in Salesforce knowledge article 005321566 lists these as out of scope[1]. Some items carry a note that a reported bug is scheduled to be fixed.
- Viewing a report in the UI
- Scheduled and subscribed report delivery
- API-based access to reports and dashboards, including integrations, connected apps and programmatic data retrieval; only interactive UI sessions require step-up
- SOQL in Developer Console and Workbench
- Free orgs such as Developer Edition, trial and scratch orgs
Salesforce's blog post of July 7, 2026 says the same for background jobs[5]:
automated background jobs will now bypass step-up via a null-session check
Two things decide whether an integration stops
- Does connecting involve a UI login? The web server flow asks for MFA at the login during authorization. The JWT bearer flow and client credentials flow have no UI login and are not affected[2]. Username-password logins may fail after MFA enforcement[6], and the OAuth username-password flow will be retired on February 20, 2027[7].
- Does the tool fetch data through the export path? A July 10, 2026 post in the Google Docs Editors Community reports that Google's Salesforce Connector failed to import reports over 2,000 rows, with an "Export and Print Reports" identity verification left pending in Salesforce[3]. An OAuth connection alone does not guarantee the fetch is treated as API access, and which path a given tool uses is not visible from outside.
Also, if an admin sets "High assurance session required" on a connected app, Salesforce says flows without a user approval step are blocked[8]. The client credentials flow has no approval step, so it would likely be blocked too.
Our test with ReportZen (2026-09-17)
ReportZen connects with the client credentials flow (server-to-server, no user interaction) and fetches reports through the Reports API, 2,000 rows at a time.
| Item | Result |
|---|---|
| Date | 2026-09-17, 07:56 JST |
| Org | Salesforce Developer Edition |
| Setup | ReportZen (Google Workspace Marketplace version, licensed), tabular report |
| Result | All 2,354 rows fetched (excluding header). No authentication prompt, no error |
| Runs | 1 |
What this shows is limited to passing the 2,000-row wall.
- It does not show that ReportZen works while step-up is active. Developer orgs are excluded from step-up authentication[1].
- It is not an upper limit. Developer Edition has 5 MB of data storage, about 2,500 records[9].
- It was a single run. Anomaly-based step-up[4] may not trigger in one run.
We will add results here once we test in a paid org (including a sandbox).
What to check when choosing or building an integration
- Which OAuth flow does it use? Does it log in with a username and password?
- Does it fetch data through the same path as a UI export?
- Does your admin require high-assurance sessions for the connected app or for reports?
- With the client credentials flow, is the run-as user's access kept to the minimum? Anyone with the keys can get a token, so Salesforce advises rotating them regularly[10].
What ReportZen does
- Loads a Salesforce report into Google Sheets as it is, no SOQL
- Pages through the report 2,000 rows at a time to get every row (license)
- Refreshes once a day, every morning (license)
- Free to install. Fetches up to 2,000 rows and CSV import work without a license
A Salesforce admin needs to create one connected app first (setup guide).
More questions
Sources (checked 2026-09-18)
- Salesforce Help 005321566: Step-up authentication for report actions https://help.salesforce.com/s/articleView?id=005321566&type=1
- Salesforce Help 005321561: MFA enforcement for all employee users https://help.salesforce.com/s/articleView?id=005321561&type=1
- Google Docs Editors Community: "Salesforce Connector: Report imports over 2K rows fail due to step-up authentication (MFA) challenge" (2026-07-10) https://support.google.com/docs/thread/449607525
- Salesforce Help 005321567: Step-up authentication on anomalous report activity https://help.salesforce.com/s/articleView?id=005321567&type=1
- Salesforce Blog: Balancing Security and Agility: Updates to Step-Up Authentication for Reports and Dashboards (2026-07-07) https://www.salesforce.com/blog/balancing-security-and-agility-updates-to-step-up-authentication-for-reports-and-dashboards/
- Salesforce Help: Troubleshoot Integration or API User Account Login Issues After MFA Enforcement https://help.salesforce.com/s/articleView?id=xcloud.mfa_passkey_integration_api_login_after_enforcement.htm&type=5
- Salesforce Release Notes: OAuth username-password flow retirement https://help.salesforce.com/s/articleView?id=release-notes.rn_security_unpw_flow_retirement.htm&release=262&type=5
- Salesforce Help: Manage session policies for connected apps https://help.salesforce.com/s/articleView?id=xcloud.connected_app_manage_session_policies.htm&type=5
- Salesforce Help: Data and File Storage Allocations https://help.salesforce.com/s/articleView?id=xcloud.overview_storage.htm&type=5
- Salesforce Help: OAuth 2.0 Client Credentials Flow for Server-to-Server Integration https://help.salesforce.com/s/articleView?id=xcloud.remoteaccess_oauth_client_credentials_flow.htm&type=5