Skip to main content
Nintex Community Menu Bar

Step-Up Authentication for Reports Advisory

  • July 11, 2026
  • 0 replies
  • 1131 views

Forum|alt.badge.img+3

 

Update - August 2026

 

Nintex DocGen now supports orgs with Step-Up Authentication enforced on reports. Report retrieval has been migrated from Salesforce report web requests to the Salesforce Reports REST API.

August 24, 2026, the new implementation will be enabled for all customers using Salesforce Reports. Before that date, contact Nintex Support to enable it for your org and validate report output early.

When a Salesforce report is used as a template, the generated output may differ from the current implementation. We recommend validating report output to ensure there are no unexpected formatting differences.

Known formatting differences include: 

Field type

Report web requests

Reports REST API

Currency

Currency code and value in separate columns

Single formatted value

Percentage

No % symbol

Includes % symbol

Number

No thousands separators

Includes commas

Boolean

0 / 1

False / True

Empty Picklist 

Blank values

-

Rich text

No character limit

Limited to 256 characters

Special characters

Pulled from the Rich Text field on the record

Displayed as represented in the report

 

Note: An option is available to preserve existing formatting where possible - contact Nintex Support. However, we encourage moving to the new format long term, as Salesforce controls the API response format. 

Testing Instructions 

For customers who have received a Step-Up Authentication extension and wish to validate the new Reports API implementation: 

  1. Before August 24, contact Nintex Support and request that the new Reports API implementation be enabled for your org. After August 24, it is enabled for all customers - no request needed.
  2. (Recommended) Verify Step-Up Authentication is configured in Salesforce:
    • Navigate to Setup → Identity Verification
    • Under Session Security Level Policies, set Reports and Dashboards to "Require periodic step-up authentication when exporting"
  3. (Recommended) Run the Salesforce report directly and attempt to export it. You should be prompted to verify your identity, confirming the setting is active. After verifying once, Salesforce may not prompt again for some period of time.
  4. Run your DDP, download the generated document, and verify the output matches expectations.

Test in a sandbox first whenever possible - ideally one without a Step-Up Authentication extension, as this provides the most accurate validation.

Refer to the help document for more details. 

 

Salesforce is strengthening its secure-by-default architecture by enforcing a mandatory, time-based step-up authentication framework. This security control is intended to provide additional protection against unauthorized data exfiltration.

The specific feature is called Step-Up Authentication for Reports. It requires users to complete an additional identity-verification challenge when exporting or printing reports if a configurable amount of time has passed since their last successful step-up challenge.

 

What Is Affected?

 

This change may affect Nintex DocGen for Salesforce customers who use Salesforce Reports as part of their document-generation processes.

Without the necessary updates or a temporary extension, report-based DocGen processes may be interrupted when Salesforce begins enforcing the step-up authentication requirement.

This change may also affect other processes or integrations that use Salesforce Reports, report exports, or report-printing actions within your Salesforce org.

Support for customers using Salesforce Reports with DocGen is now available. See the update at the top of this post.

 

Salesforce Enforcement Timeline

 

Salesforce began enforcing this requirement in sandbox environments on June 17, 2026, with the rollout occurring over approximately seven days.

Enforcement in production environments began on July 1, 2026, with a phased rollout over approximately 30 days.

This is not a new Salesforce feature. Rather, Salesforce is beginning to enforce an existing security control.

Salesforce has published guidance to help customers prepare for the upcoming change:

Prepare for the Upcoming Step-Up Authentication Requirements on Report Actions

 

Recommendations for Nintex DocGen Customers

 

1. Review Salesforce’s preparation guidance

Customers who use Salesforce Reports should review the Salesforce preparation guide linked above.

Because this change may affect more than Nintex DocGen, customers should also assess how Salesforce Reports, report exports, and report-printing actions are used throughout their Salesforce org.

2. Request an enforcement extension

To give customers additional time to prepare and help prevent disruption to their business processes, Salesforce is approving temporary extensions that exempt eligible orgs from enforcement through October 1, 2026.

Nintex DocGen customers who use Salesforce Reports should open a case with Salesforce Support as soon as possible.

When submitting the case:

  1. Include the affected Salesforce Org ID.
  2. Explain that the org uses Salesforce Reports with Nintex DocGen.
  3. Request an extension for Step-Up Authentication for Reports through October 1, 2026.

3. Update the Session Security Level Policy

After Salesforce confirms that the extension has been applied:

  1. Log in to the affected Salesforce org.
  2. Go to Salesforce Setup.
  3. Search for and select Identity Verification from the sidebar.
  4. Locate Session Security Level Policies.
  5. Set Reports and Dashboards to None.

If this option is unavailable or disabled, contact Salesforce Support and confirm that the extension was applied to the correct Salesforce Org ID.

 

Questions?

 

Reach out to our Support team for assistance.