Skip to content
TOPIC

Salesforce Admin.

POSTS
37
OLDEST
2026
NEWEST
2026

All posts.

AUG 26 2026

Salesforce Strips Non-Public Fields from Aura Action Responses in Spring '27: The Break Only Shows in the Browser

Spring '27 strips non-public system fields from Aura action responses. Why components fail silently, and why no build or Apex test will catch it first.

SalesforceSecuritylwcTroubleshootingsalesforce-admin
AUG 25 2026

Salesforce Winter '27 Requires Use Any API Auth for SOAP login(): Find Your Exposure First

Winter '27 requires the Use Any API Auth permission for SOAP API login(), or the call errors. The queries to size your exposure and check who holds it.

SalesforceSecuritysalesforce-adminIntegrationAuthentication
AUG 9 2026

INSUFFICIENT_ACCESS_ON_CROSS_REFERENCE_ENTITY: The Error Names the Wrong Record

The record you are saving is not the problem. It is the one you are pointing at. How to find the real record and why granting Modify All is the wrong fix.

SalesforceTroubleshootingLeast Privilegesalesforce-adminApex
AUG 6 2026

Sending Email from Salesforce Securely: SMTP Is Not Encrypted by Default

SMTP is cleartext by design and TLS is opportunistic. Why Preferred Verify still sends in the clear, and what to configure so email is actually protected.

SalesforceSecuritysalesforce-adminComplianceAuthentication
AUG 4 2026

Salesforce Winter '27 Security Readiness: The Release Updates and the Sandbox Window to Test Them

Winter '27 enforces two security changes, not the five widely listed. Three slipped to 2027 or were cancelled. The dates, what breaks, and how to test.

SalesforceSecuritysalesforce-adminComplianceIntegration
AUG 2 2026

Migrating Legacy Named Credentials Before They Become the Next Salesforce Deadline

Legacy Named Credentials mix secrets and access in one record with no permission set control. Migrate during the Winter '27 window, and how the split works.

SalesforceSecuritysalesforce-adminIntegrationLeast Privilege
AUG 1 2026

Salesforce Cancelled the Profile Permissions Retirement. Migrate Anyway.

The Spring '26 deadline that forced permission set migrations is gone. What the reversal reveals, and why the deadline was never the reason to migrate.

SalesforceSecuritysalesforce-adminLeast PrivilegeUser Management
JUL 31 2026

Salesforce Stops Supporting Incorrect Instanced URLs in API Traffic, Now Spring '27

Salesforce postponed the instanced URL enforcement to Spring '27, a third slip. Why hardcoded endpoints break, and how to control the cutover yourself.

SalesforceSecuritysalesforce-adminIntegrationAPI
JUL 30 2026

Salesforce Licence Audit: What You Are Paying For and What Is Idle

Idle licences and excess permissions are the same failure: nobody removes access when the need ends. One audit answers both questions at the same time.

SalesforceArchitectureLeast Privilegesalesforce-adminOrg Strategy
JUL 29 2026

Salesforce Winter '27 Turns On Profile Filtering: What Breaks, and How to Test It First

Winter '27 enforces Profile Filtering, so users see only their own profile name. What breaks in Flows, validation rules and Apex, and how to test it early.

SalesforceSecuritysalesforce-adminUser ManagementLeast Privilege
JUL 27 2026

Salesforce Is Retiring the Email Change Verification Exemption: Set Up Authorized Email Domains Before 1 December 2026

Adopt Authorized Email Domains was cancelled. Its replacement enforces 1 December 2026. How to keep your email verification exception before it lands.

SalesforceSecuritysalesforce-adminUser ManagementCompliance
JUL 25 2026

Salesforce Report-Export Step-Up Enforcement: The Known Issues and Gotchas Nobody Warned You About

Blocked exports, a broken Login As, and RPA jobs failing: the practitioner known issues behind Salesforce report-export step-up enforcement in July 2026.

SalesforceSecurityEvent MonitoringShieldCompliancesalesforce-admin
JUL 24 2026

Sizing a Salesforce Access Model: Team Shape, Internal vs External Admins, and What It Costs to Run

A full access model is not always the right one. How to size it to your team, flex it for external delivery partners, and what the whole thing costs to run.

SalesforceSecurityLeast Privilegesalesforce-adminDevOpsCompliance
JUL 22 2026

A Least-Privilege Access Model for the Salesforce Delivery Team: Tiers, Roles, and Where the Escalation Chain Breaks

How to tier sandboxes, layer profiles and permission set groups, and use the one fact that stops a developer escalating from a sandbox into your production org.

SalesforceSecurityLeast Privilegesalesforce-adminDevOps
JUL 20 2026

Why Your Developers Don't Need Modify All Data (And What They Actually Need Instead)

Modify All Data is org-wide read and write that does not even override field-level security. Here are the five real requests behind it, and what each one needs.

SalesforceSecurityLeast Privilegesalesforce-adminApex
JUL 18 2026

Agentforce Agent User Least Privilege: What the Wizard Grants, What Your Agent Actually Needs, and How to Audit the Gap

What the Agentforce setup wizard grants your service agent user, what it actually needs, and how to audit both before an attacker maps the gap for you.

SalesforceSecurityAgentforceLeast PrivilegeEvent Monitoringsalesforce-admin
JUL 16 2026

Locked Out After Salesforce MFA Enforcement: Recovery Paths, Temporary Codes, and the Break-Glass Account You Should Have Built

Locked out after Salesforce MFA enforcement? The recovery paths, temporary codes, Support realities, and how to build a break-glass admin account for your org.

SalesforceSecurityMFAAuthenticationsalesforce-adminIncident Response
JUL 14 2026

Audit Your Agentforce Footprint: Every Agent, Agent User, and Permission in One Pass

Inventory every Agentforce agent, agent user, and permission with sf CLI and SOQL: the exact queries to see what your agents can touch, and from where.

SalesforceSecurityAgentforcesf-clisalesforce-adminDevOps
JUL 12 2026

Post-ForcedLeak: Hardening Agentforce Against Prompt Injection (The Setup Steps Nobody Published)

ForcedLeak turned a $5 domain into an Agentforce data-exfiltration channel. The concrete Setup hardening steps to shrink your prompt-injection blast radius.

SalesforceAgentforceSecurityAIsalesforce-adminEvent Monitoring
JUL 10 2026

IPP 3A Is Live: Building New Zealand's Indirect-Collection Notice into Salesforce

New Zealand's IPP 3A now requires notice when you collect personal data indirectly. Build compliance into Salesforce with source fields, a Flow, one report.

SalesforceSecurityComplianceNZ Privacy Actsalesforce-admin
JUL 7 2026

Salesforce MFA Enforcement Update: What Was Paused, What Still Applies, and the Revised 2026 Dates

Salesforce paused its all-employee MFA enforcement over a security-key enrolment bug and revised the 2026 dates. Here is what moved and what still applies.

SalesforceMFASecurityAuthenticationCompliancesalesforce-admin
JUL 6 2026

Fixing 'Could Not Infer a Metadata Type' in the Salesforce CLI

The Salesforce CLI error 'Could not infer a metadata type' has one message and several causes. A decision tree to find which one you hit, and the fix for each.

Salesforcesf-clisalesforce-adminDevOpsmetadataTroubleshooting
JUL 2 2026

Salesforce Retires the OAuth Username-Password Flow on 20 February 2027: Migrate Before Your Integrations Break

Salesforce postponed the OAuth 2.0 username-password flow retirement to 20 February 2027. What breaks, how to find affected integrations, and how to migrate.

SalesforceSecurityOAuthIntegrationsalesforce-adminAuthentication
JUN 21 2026

Salesforce Summer '26: The SAML Retirement and Apex Secure-by-Default Changes That Break Orgs Quietly

Two Summer '26 changes break orgs without warning: retiring single-configuration SAML stops SSO logins, and Apex now defaults to with sharing. What to check, where.

SalesforceSecuritySSOApexsalesforce-adminAuthentication
JUN 19 2026

Salesforce Security Enforcement in 2026: Every Change, Date, and What Admins Must Do

Across 2026 Salesforce turns a stack of security recommendations into hard enforcement: MFA, report step-up auth, IP blocking and more. The full list and dates.

SalesforceSecurityMFAsalesforce-adminComplianceAuthentication
MAY 21 2026

Org-Dependent Packages: How to Edit in a Sandbox, Pull Changes, and Create a Merge Request

The complete workflow for org-dependent Salesforce packages: make changes in a sandbox, retrieve them with sf CLI, commit to git, and open a merge request. Step by step.

Salesforcesf-cligitunlocked-packageorg-dependentsalesforce-adminDevOps
MAY 19 2026

Deploying Salesforce Metadata with sf CLI: From Sandbox to Production

Deploy Salesforce metadata from your local project back to a sandbox or production org using sf CLI, including check-only deploys, reading results, and what to do when deploy fails.

Salesforcesf-clideploymetadatasalesforce-adminDevelopment Best Practices
MAY 17 2026

Git Basics for Salesforce Admins: Track Your Org Changes with Version Control

Learn the six git commands every Salesforce admin needs: init, status, add, commit, log, and diff. Includes a real workflow: retrieve a Flow, commit it, change it, see the diff.

Salesforcegitsalesforce-adminversion-controlDevelopment Best Practices
MAY 15 2026

Fetching CRM Analytics & Einstein Discovery Metadata with sf CLI: WaveDashboard, WaveRecipe, DiscoveryStory

How to retrieve CRM Analytics (Wave) and Einstein Discovery metadata from Salesforce using sf CLI, including what can and cannot be retrieved via the Metadata API.

Salesforcesf-clisalesforce-admincrm-analyticseinstein-discoverymetadata
MAY 13 2026

Fetching OmniStudio Metadata with sf CLI: OmniScript, DataRaptor, FlexCard, Integration Procedure

How to retrieve OmniScript, DataRaptor (OmniDataTransform), FlexCard (OmniUiCard), and Integration Procedure metadata from Salesforce using sf CLI, with standard runtime requirements and deployment caveats.

Salesforcesf-clisalesforce-adminOmniStudiometadata
MAY 11 2026

Fetching Code Metadata from Salesforce with sf CLI: ApexClass, ApexTrigger, LWC, Aura

How to retrieve ApexClass, ApexTrigger, LightningComponentBundle, and AuraDefinitionBundle metadata from Salesforce using sf CLI, for admins who oversee developers or need to deploy code.

Salesforcesf-clisalesforce-adminmetadataApexlwc
MAY 9 2026

Fetching Security Metadata from Salesforce with sf CLI: Profile, PermissionSet, Role

How to retrieve Profile, PermissionSet, PermissionSetGroup, MutingPermissionSet, and Role metadata from Salesforce using sf CLI, including partial retrieval patterns for large Profile XML.

Salesforcesf-clisalesforce-adminmetadataSecurity
MAY 7 2026

Fetching Automation Metadata from Salesforce with sf CLI: Flow, WorkflowRule, ApprovalProcess

How to retrieve Flow, WorkflowRule, ProcessBuilder, and ApprovalProcess metadata from Salesforce using sf CLI, with source format, MDAPI format, and package.xml examples.

Salesforcesf-clisalesforce-adminmetadataautomation
MAY 5 2026

Fetching Custom Configuration Metadata from Salesforce with sf CLI

How to retrieve CustomObject, CustomField, Layout, FlexiPage, RecordType, and CompactLayout metadata from Salesforce using sf CLI: source format, MDAPI format, and package.xml.

Salesforcesf-clisalesforce-adminmetadataversion-control
MAY 3 2026

Connecting sf CLI to Your Salesforce Org: sf org login web Complete Guide

How to connect sf CLI to your Salesforce org using sf org login web. Covers sandbox vs production login, org aliases, and verifying your connection.

Salesforcesf-clisalesforce-adminversion-controlDevOps
MAY 1 2026

Setting Up Your Environment: Terminal, sf CLI, and Git for Salesforce Admins

Step-by-step guide to setting up your terminal, sf CLI, and git on Windows or macOS: everything a Salesforce admin needs before working with metadata.

Salesforcesf-cligitsalesforce-adminsetupDevelopment Best Practices
APR 29 2026

What is Version Control and Why Every Salesforce Admin Needs It

Version control for Salesforce admins explained from scratch: what it is, why your org needs it, and what you can do with git that you can't do today.

Salesforcegitversion-controlsalesforce-adminDevelopment Best Practices