Following my previous article dealing with MFA enforcements (and stricter « Phishing-Resistant » MFA for System Admin users, or users with powerful administrative permissions), Salesforce also recently communicated on changes on Transaction Security Policies, that will be released after Salesforce’s Summer’26 release.
As you know, large report exports may be easily exploited for data theft or leaks (from out of the company, or by someone stealing data before leaving). With Salesforce’s Event Monitoring (Shield) and some robust Transaction Security Policies, Salesforce platform provides a proactive layer of defense to identify and block unauthorized data leak.
So what is the change for Summer’26 ?
STRICTER TSP MANAGEMENT REQUIREMENTS
Managing your critical Transaction Security Policies (TSP) will soon require a « double check » approach. Indeed, to be able to create, edit, or activate / deactivate TSP records, users would now need to be assigned both the following permissions :
- The « traditional » Customize Application permission, used for instance customization.
- With the upcoming Modify Transaction Security Policy permission.
Salesforce also mentions that if a user is trying to perform these actions through the Setup User Interface, Salesforce will prompt this user for an extra identity verification step, in order to ensure the changes are intentional and well realized by the logged-in user.
🔜▶️ As for now, please check your System Administrators, and all users granted with the Customize Application permission, and start identifying who should be assigned the new Modify Transaction Security Policy permission.
A NEW DEFAUT POLICY FOR LARGE REPORT EXPORTS
To prevent data leaks, due to badly configured instances, or Salesforce products not yet fully mastered by clients, Salesforce will also roll out a default Transaction Security Policy, dealing especially with report export use case.
- This policy will concern any UI-based report export that exceeds 10 000 records.
- In this case, Salesforce will automatically require an extra identity verification step before the export can continue.
🔜▶️ That will allow for all new orgs / updated orgs to have at least one default security policy. However, you will need to review, tweak or not, and activate this default Transaction Security Policy, so that it will match your data volume / sensitivity and criticality of your data.
To read more on the subject
- Help Article – Prepare for Transaction Security Policy Enhancements : https://help.salesforce.com/s/articleView?id=005321565&type=1&language=en_US
- Platform’s security-related roadmap : https://help.salesforce.com/s/articleView?id=005317465&type=1
- Trailhead module on this topic « Enhanced Transaction Security » : https://trailhead.salesforce.com/content/learn/modules/enhanced_transaction_security
- Salesforce Shield product page : https://www.salesforce.com/platform/shield/
