Here Are the Four Changes to Plan for Now
If your organization runs Salesforce Marketing Cloud Engagement (MCE), you’ve probably already seen an email from Salesforce about upcoming security changes. It’s easy to let these notices sit in an inbox, especially when they arrive without an actionable list.
There are four changes worth your attention. Two are already in effect. Two more are coming by January 13, 2027.
1. API Client Secrets Now Expire
If your MCE environment connects to other systems through the API (and most do), those connections rely on a client secret, essentially a password for machine-to-machine communication. Salesforce has introduced an expiration policy for these secrets. Any secret that hasn’t been rotated will expire on September 30, 2026. Going forward, secrets expire automatically every 180 days.
This is a meaningful shift. In the past, a client secret was something you set up once and rarely thought about again. Now it needs to be treated as a recurring maintenance task.
What to do: Check your Installed Packages page in Setup. It includes a summary table showing the expiration date for every client secret in your account. If something is close to expiring, generate a new secret, update the systems that use it, test that everything still works, and then activate the new secret. If a secret expires, it will break the API connection you have.
2. IP Allowlisting Is Becoming Mandatory
Salesforce is requiring all MCE accounts to enable IP allowlisting in enforcement mode, meaning logins and API requests are only permitted from approved IP addresses. Everything else gets blocked. This is rolling out in phases, with full enforcement required by January 13, 2027.
This one deserves a bit more thought than it might seem at first. Salesforce will generate a recommended list of IP ranges based on your account’s recent login activity. That generated list works best when your team logs in from a small, predictable set of locations like an office network or a VPN. If your team works remotely or logs in from many different places, it’s worth putting a real plan in place rather than accepting the default recommendation.
What to do: Turn on monitoring mode first (Salesforce calls this “Log Allowlist Violations”) for a couple of weeks to see what your actual login traffic looks like. Use that information to build an accurate list before switching to full enforcement. If your team is distributed, consider routing MCE access through a VPN with a fixed IP address, so you’re maintaining one stable entry point instead of dozens of shifting ones.
3. Phishing Resistant MFA for Admins
Starting January 13, 2027, MCE administrators will be required to use a phishing resistant method of multi factor authentication, such as a FIDO2 security key, Windows Hello or Apple Touch ID. Traditional MFA methods like text message codes won’t satisfy this requirement for admin accounts. Admins who haven’t set this up by the deadline will be locked out.
What to do: Identify everyone with administrator access to your MCE account now. Give them time to register a supported authentication method and get comfortable using it before the deadline arrives.
4. MFA Requirements for Single Sign On Users
If your organization uses single sign on to access MCE, your identity provider (Okta, for example) will need to pass specific authentication signals confirming that MFA was completed. This also takes effect January 13, 2027. If your identity provider isn’t configured to send these signals, users won’t be able to log in through SSO once the requirement is enforced.
What to do: This one isn’t something your marketing team can solve alone. Loop in whoever manages your identity provider now (probably IT) so there’s time to test the configuration well before the deadline.
The Bigger Picture
None of these changes are a reason to panic, but together they represent a real shift in how much ongoing attention your MCE environment needs. Secrets that used to be permanent now expire. Logins that used to come from anywhere now need to come from somewhere specific. Authentication that used to be a single factor now needs to be resistant to phishing.
If you want a second opinion on how any of this applies to your specific MCE setup, we’re happy to talk it through with you.