What's New In 26R2.2
This topic provides information about the Veeva CRM 26R2.2 release, including important dates and release announcements.
All dates listed are subject to change.
Dates to Remember
- September 3, 2026 – Maintenance Notes available
- September 10, 2026 – Sandbox Release
- September 17, 2026 – Production Release
Release Notes
The following items are now available:
- What's New In Veeva CRM 26R2.2
- Announcements
- User Visible and Behavior Changes (UVCs)
- 26R2.2 Maintenance Notes
Announcements
Multi-Factor Authentication (MFA) – Now Mandatory for All Users, Including Admins, in Sandbox & Production Orgs
Starting in July of 2026, Multi-Factor Authentication (MFA) will be required for all users in Sandbox & Production orgs, including admins. Ensure MFA is fully configured for your users ahead of Salesforce's MFA deadlines. While phishing-resistant MFA is not required for standard (non-privileged) users, it is strongly recommended. For details, see Salesforce Security Updates and MFA Requirements.
Changes to Salesforce Security Control Requirements
Salesforce plans to require the implementation of additional security controls and settings. Take the following actions to ensure your settings meet Salesforce’s security requirements:
- Require Multifactor Authentication (MFA): MFA is mandatory for all Production Orgs as of June 2026. Customers must ensure that MFA is fully set up before June. While in the past Veeva was able to request a 90-day rollback for customers, Salesforce will no longer approve these requests.
Despite communications suggesting otherwise, Salesforce has confirmed that MFA will not be enforced in Sandbox Orgs, though it remains strongly recommended.
- Ensure all System Administrator users adopt phishing-resistant MFA for login: While not mandatory, all System Administrator users are strongly encouraged to adopt phishing-resistant MFA for login. This is considered a security best practice to protect your most privileged accounts.
- Restrict login IP addresses in profiles: Beginning with the Winter '26 release, Salesforce will enforce limits on login IP ranges for specific profiles. If your organization uses profile-level IP restrictions, we recommend reviewing your current configurations now to ensure they will remain within the new limits.
The following items are standard security best practices that all customers should continue to follow:
- Enable a Transaction Security Policy (TSP) that restricts large data exports
- Avoid connecting from anonymizing proxies or high-risk IP addresses
For more details on these updates, refer to Salesforce’s New Security Control Requirements page. This page is updated regularly — we encourage you to monitor the Change Log table there for the latest information.
If you have any questions or concerns, please reach out to Veeva Support.
Changes to Public Key Infrastructure in Salesforce
Salesforce has announced upcoming mandatory changes to Public Key Infrastructure. Veeva standard integrations with Salesforce are not impacted. However, Veeva recommends customers review any custom-built integrations within their environments to ensure compliance with these upcoming changes.
End of Support
See End of Support for a list of deprecated features, devices, and OS versions.
User Visible and Behavior Changes (UVCs)
Users are able to use the following functionality immediately.
Authentication
|
Platform |
Description |
Before |
After |
|---|---|---|---|
| iPad |
Selecting Go Online now routes users directly to the standard Salesforce browser login. The first time a user selects Go Online from the navigation bar or an action menu they are prompted to complete their standard organization login, including any configured Single Sign-On (SSO) and MFA requirements. Subsequent Go Online actions launch without requiring a login, until the browser session expires. Previously, users were prompted to register for a Salesforce passkey or MFA when using the Go Online feature in Veeva CRM. |
n/a |
n/a |

