Salesforce Security in 2026: Key Changes That Reduce Risk and Strengthen Trust
By Molly HenrySecurity has always been a core part of Salesforce, but recent platform updates reflect a broader shift in how organizations protect data, users, and business operations. As cyber threats become more advanced and compliance expectations continue to rise, Salesforce is strengthening its security framework to help customers better manage risk and maintain trust.
In May 2026, Salesforce introduced several important security enhancements that affect authentication, email communications, integrations, AI governance, and platform monitoring. For administrators and business leaders, understanding these changes is essential not only for compliance but also for safeguarding sensitive information and supporting long-term business resilience.
Multi-Factor Authentication Is Now a Baseline Expectation
Salesforce continues to expand multi-factor authentication (MFA) requirements across its platform, reinforcing MFA as a fundamental security control rather than an optional safeguard.
All employee users are expected to use MFA, and Salesforce is encouraging stronger authentication methods for administrators and other privileged users. Options such as security keys and built-in device authenticators provide greater protection against phishing attacks and credential theft than traditional passwords alone.
Another key focus is step-up authentication. This approach requires users to verify their identity again before performing sensitive actions, even after they have successfully logged in. Additional verification may be needed when exporting reports, accessing confidential information, or working with large volumes of data.
These enhancements support a modern security model where access is continuously validated instead of automatically trusted after login. The result is stronger protection against unauthorized access and reduced exposure to security threats
Email Verification Is Now a Security Requirement
Beginning with the Spring ’26 release, Salesforce requires verification of any domain used to send emails from the platform. Without verification, outbound emails may fail to deliver, often with little visibility into the issue.
This requirement applies to emails sent through:
- Standard Salesforce email functionality
- Salesforce Flow
- Apex code
- Workflow email alerts
For most organizations, domain verification is completed through DomainKeys Identified Mail (DKIM) or the Authorized Email Domains process. Both methods require updates to DNS records.
While public email services such as Gmail and Outlook are generally exempt, most corporate domains must be verified. Organizations that rely on Salesforce-generated emails should address this requirement promptly to avoid delivery issues and ensure customers continue receiving important communications.
Stronger Controls for Applications and Integrations
Salesforce is also evolving how organizations manage applications and integrations connected to the platform. The creation of new Connected Apps is now restricted by default, and External Client Apps are becoming the preferred option.
This shift aligns with Salesforce’s increased focus on governance and access control. External Client Apps provide administrators with stronger oversight by requiring approval for application access, improving OAuth permission management, and establishing clearer ownership. They also offer better visibility into how applications are used across the organization.
Although existing Connected Apps remain supported, organizations should use this opportunity to review their integration landscape. Administrators should identify applications that are no longer needed, confirm who has access, and evaluate whether permissions still align with business requirements
Understanding AI Data Usage and Opt-Out Controls
As Salesforce expands its AI capabilities, organizations are paying closer attention to how data supports these technologies.
Some Salesforce Einstein AI features use global models trained with aggregated and anonymized customer data from multiple organizations. To provide greater transparency and customer control, Salesforce now allows organizations to opt out of having their data used for AI model training as well as certain research and development activities.
This option is particularly valuable for organizations operating in regulated industries or those with strict privacy and data governance requirements.
As AI becomes more integrated into daily business processes, organizations should regularly review and document these settings within their governance framework. Clear policies around AI data usage help balance innovation with privacy, compliance, and responsible data management.
My Trust Center Delivers More Relevant Insights
Salesforce has enhanced the way organizations monitor platform health, security events, and maintenance activities through My Trust Center.
In the past, administrators often had to review broad instance-level notifications to determine whether an update applied to their environment. My Trust Center improves that experience by delivering information tailored to each organization’s specific Salesforce instance.
Using a Trailblazer account, administrators can access organization-specific maintenance schedules, operational updates, security notifications, and alerts. This personalized approach helps reduce unnecessary noise and allows teams to focus on information that requires action.
With better visibility into platform events, organizations can respond more quickly to issues, plan more effectively, and improve operational readiness.
Health Check Remains an Essential Security Tool
Although not new, Health Check continues to be one of the most valuable tools for assessing Salesforce security posture.
Health Check evaluates how closely an organization’s configuration aligns with Salesforce-recommended security settings, including:
- Password policies
- Session management controls
- Multi-factor authentication requirements
- General security configurations
The tool generates a security score and highlights areas where settings fall below recommended standards. Because Salesforce environments continually evolve through user growth, configuration changes, and new integrations, security gaps can emerge over time. Running Health Check regularly helps organizations identify risks early, prioritize remediation efforts, and maintain stronger security controls.
What These Changes Mean for Your Organization
From stronger authentication requirements and mandatory email verification to improved integration governance and greater control over AI data usage, Salesforce’s 2026 security updates reflect a broader shift toward continuous security management and accountability.
Security is no longer solely an IT concern. It is a business priority that directly affects compliance, operational resilience, customer trust, and long-term growth.
Organizations that take the time to understand these changes, strengthen their controls, and regularly assess their Salesforce environments will be better positioned to reduce risk, protect valuable business data, and support long-term growth.
Whether you're addressing new security requirements, improving governance, or optimizing your Salesforce environment, Citrin Cooperman can help. Reach out to learn how our experienced professionals can support your security and compliance goals.
Latest Articles
Salesforce Security in 2026: Key Changes That Reduce Risk and Strengthen Trust
Read More
Redefining ERM in the Age of Shadow AI and Third-Party Risk
Read More
CMMC Phase II: A Tactical Pause, Not a Strategic Retreat
Read More
OMB Proposes Significant Changes to Uniform Guidance
Read More
