ReportZen

FAQ / Last updated 2026-09-19 / By Okamoto Tools

Do report integrations keep working after step-up authentication and MFA enforcement in Japan (Sept 1, 2026)?

According to Salesforce's official FAQ, step-up authentication applies only to interactive UI sessions. API access to reports (integrations, connected apps, programmatic retrieval) and scheduled report subscriptions are excluded[1]. The September 1 MFA enforcement covers UI login, and Salesforce states that integrations using the JWT bearer flow or client credentials flow are not affected[2]. However, a tool connected through the API can still be blocked if it fetches data through the same path as a UI export: users of Google's Salesforce Connector reported that report imports over 2,000 rows fail due to step-up authentication[3].

July step-up authentication and September MFA are separate changes

The extra check on every export comes from step-up authentication, not from the September MFA enforcement. Dates are for production orgs; sandboxes started earlier.

WhenChangeWho
Rolled out over ~30 days from July 1, 2026Step-up authentication (an extra MFA check) on report export. Admins set the re-check interval from 1 to 120 minutes[1]Paid production and sandbox orgs
From July 27, 2026Step-up when unusual report activity is detected[4]Same (currently mainly UI downloads)
September 1, 2026 (Japan and Korea)MFA enforced on UI login for all employee users[2]Paid production and sandbox orgs

What the official FAQ excludes

The FAQ in Salesforce knowledge article 005321566 lists these as out of scope[1]. Some items carry a note that a reported bug is scheduled to be fixed.

Salesforce's blog post of July 7, 2026 says the same for background jobs[5]:

automated background jobs will now bypass step-up via a null-session check

Two things decide whether an integration stops

  1. Does connecting involve a UI login? The web server flow asks for MFA at the login during authorization. The JWT bearer flow and client credentials flow have no UI login and are not affected[2]. Username-password logins may fail after MFA enforcement[6], and the OAuth username-password flow will be retired on February 20, 2027[7].
  2. Does the tool fetch data through the export path? A July 10, 2026 post in the Google Docs Editors Community reports that Google's Salesforce Connector failed to import reports over 2,000 rows, with an "Export and Print Reports" identity verification left pending in Salesforce[3]. An OAuth connection alone does not guarantee the fetch is treated as API access, and which path a given tool uses is not visible from outside.

Also, if an admin sets "High assurance session required" on a connected app, Salesforce says flows without a user approval step are blocked[8]. The client credentials flow has no approval step, so it would likely be blocked too.

Our test with ReportZen (2026-09-17)

ReportZen connects with the client credentials flow (server-to-server, no user interaction) and fetches reports through the Reports API, 2,000 rows at a time.

ItemResult
Date2026-09-17, 07:56 JST
OrgSalesforce Developer Edition
SetupReportZen (Google Workspace Marketplace version, licensed), tabular report
ResultAll 2,354 rows fetched (excluding header). No authentication prompt, no error
Runs1

What this shows is limited to passing the 2,000-row wall.

We will add results here once we test in a paid org (including a sandbox).

What to check when choosing or building an integration

  1. Which OAuth flow does it use? Does it log in with a username and password?
  2. Does it fetch data through the same path as a UI export?
  3. Does your admin require high-assurance sessions for the connected app or for reports?
  4. With the client credentials flow, is the run-as user's access kept to the minimum? Anyone with the keys can get a token, so Salesforce advises rotating them regularly[10].

What ReportZen does

Get it on Google Workspace Marketplace

A Salesforce admin needs to create one connected app first (setup guide).

More questions

Sources (checked 2026-09-18)

  1. Salesforce Help 005321566: Step-up authentication for report actions https://help.salesforce.com/s/articleView?id=005321566&type=1
  2. Salesforce Help 005321561: MFA enforcement for all employee users https://help.salesforce.com/s/articleView?id=005321561&type=1
  3. Google Docs Editors Community: "Salesforce Connector: Report imports over 2K rows fail due to step-up authentication (MFA) challenge" (2026-07-10) https://support.google.com/docs/thread/449607525
  4. Salesforce Help 005321567: Step-up authentication on anomalous report activity https://help.salesforce.com/s/articleView?id=005321567&type=1
  5. Salesforce Blog: Balancing Security and Agility: Updates to Step-Up Authentication for Reports and Dashboards (2026-07-07) https://www.salesforce.com/blog/balancing-security-and-agility-updates-to-step-up-authentication-for-reports-and-dashboards/
  6. Salesforce Help: Troubleshoot Integration or API User Account Login Issues After MFA Enforcement https://help.salesforce.com/s/articleView?id=xcloud.mfa_passkey_integration_api_login_after_enforcement.htm&type=5
  7. Salesforce Release Notes: OAuth username-password flow retirement https://help.salesforce.com/s/articleView?id=release-notes.rn_security_unpw_flow_retirement.htm&release=262&type=5
  8. Salesforce Help: Manage session policies for connected apps https://help.salesforce.com/s/articleView?id=xcloud.connected_app_manage_session_policies.htm&type=5
  9. Salesforce Help: Data and File Storage Allocations https://help.salesforce.com/s/articleView?id=xcloud.overview_storage.htm&type=5
  10. Salesforce Help: OAuth 2.0 Client Credentials Flow for Server-to-Server Integration https://help.salesforce.com/s/articleView?id=xcloud.remoteaccess_oauth_client_credentials_flow.htm&type=5