Authentication.
All posts.
An Experience Cloud Tile Launch Is a Session Hand-Off, Not a Login
Moving between Experience Cloud sites reuses one session, so a Login Flow on the destination never fires. Here is how to prove it from the login records.
SAME_ORG_SSO: Why One Experience Cloud Site Cannot Be an Identity Provider for Another
Salesforce blocks OIDC between two Experience Cloud sites in one org. Why a site is not an identity authority, and why SAML is the one route still open.
Salesforce Restricts the OAuth Device Flow on 30 November 2026: Your Connected App Has to Become an External Client App
From 30 November 2026 the OAuth device flow works only from local external client apps. Connected apps that use it must migrate or stop authenticating.
Salesforce Retires the OAuth User-Agent Flows on 20 February 2027: Move to Web-Server Flow with PKCE
The OAuth user-agent and hybrid user-agent flows retire on 20 February 2027. What breaks, why a token in the URL is the problem, and where to move next.
Salesforce Winter '27 Requires Use Any API Auth for SOAP login(): Find Your Exposure First
Winter '27 requires the Use Any API Auth permission for SOAP API login(), or the call errors. The queries to size your exposure and check who holds it.
Salesforce Certificate Trust Store: Your Own Root CAs, for Named Credentials Only
Winter '27 lets you upload and manage your own root certificates in Salesforce. The scope is narrower than it first looks, and that scope is the story.
Sending Email from Salesforce Securely: SMTP Is Not Encrypted by Default
SMTP is cleartext by design and TLS is opportunistic. Why Preferred Verify still sends in the clear, and what to configure so email is actually protected.
Locked Out After Salesforce MFA Enforcement: Recovery Paths, Temporary Codes, and the Break-Glass Account You Should Have Built
Locked out after Salesforce MFA enforcement? The recovery paths, temporary codes, Support realities, and how to build a break-glass admin account for your org.
Salesforce MFA Enforcement Update: What Was Paused, What Still Applies, and the Revised 2026 Dates
Salesforce paused its all-employee MFA enforcement over a security-key enrolment bug and revised the 2026 dates. Here is what moved and what still applies.
Salesforce Retires the OAuth Username-Password Flow on 20 February 2027: Migrate Before Your Integrations Break
Salesforce postponed the OAuth 2.0 username-password flow retirement to 20 February 2027. What breaks, how to find affected integrations, and how to migrate.
Salesforce Summer '26: The SAML Retirement and Apex Secure-by-Default Changes That Break Orgs Quietly
Two Summer '26 changes break orgs without warning: retiring single-configuration SAML stops SSO logins, and Apex now defaults to with sharing. What to check, where.
Salesforce Security Enforcement in 2026: Every Change, Date, and What Admins Must Do
Across 2026 Salesforce turns a stack of security recommendations into hard enforcement: MFA, report step-up auth, IP blocking and more. The full list and dates.
Salesforce MFA Enforcement in 2026: What Admins Must Verify and Do
Salesforce moves from contractual MFA to hard enforcement in mid-2026, with a stricter phishing-resistant bar for admins. How to verify your org and comply.