Skip to content
TOPIC

Security.

POSTS
46
OLDEST
2014
NEWEST
2026

All posts.

AUG 30 2026

Salesforce Restricts the OAuth Device Flow on 30 November 2026: Your Connected App Has to Become an External Client App

From 30 November 2026 the OAuth device flow works only from local external client apps. Connected apps that use it must migrate or stop authenticating.

SalesforceSecurityIntegrationAuthenticationConnected Apps
AUG 28 2026

Salesforce Retires the OAuth User-Agent Flows on 20 February 2027: Move to Web-Server Flow with PKCE

The OAuth user-agent and hybrid user-agent flows retire on 20 February 2027. What breaks, why a token in the URL is the problem, and where to move next.

SalesforceSecurityIntegrationAuthenticationConnected Apps
AUG 26 2026

Salesforce Strips Non-Public Fields from Aura Action Responses in Spring '27: The Break Only Shows in the Browser

Spring '27 strips non-public system fields from Aura action responses. Why components fail silently, and why no build or Apex test will catch it first.

SalesforceSecuritylwcTroubleshootingsalesforce-admin
AUG 25 2026

Salesforce Winter '27 Requires Use Any API Auth for SOAP login(): Find Your Exposure First

Winter '27 requires the Use Any API Auth permission for SOAP API login(), or the call errors. The queries to size your exposure and check who holds it.

SalesforceSecuritysalesforce-adminIntegrationAuthentication
AUG 24 2026

Salesforce Certificate Trust Store: Your Own Root CAs, for Named Credentials Only

Winter '27 lets you upload and manage your own root certificates in Salesforce. The scope is narrower than it first looks, and that scope is the story.

SalesforceSecurityIntegrationAuthenticationCompliance
AUG 22 2026

Salesforce Lets You Allowlist Chrome Extensions on Experience Cloud Sites

Winter '27 lets you allowlist specific Chrome extensions as trusted URLs on an Experience Cloud site. What it controls, and the two limits that matter.

SalesforceSecurityExperience CloudGuest UserCompliance
AUG 20 2026

Migrating Connected Apps to External Client Apps: The Tool Now Covers Packaged and Distributed Apps

Connected apps end in Summer '27. The migration tool now covers packaged and distributed apps, and keeps existing tokens and sessions valid through it.

SalesforceSecurityIntegrationConnected AppsDevOps
AUG 6 2026

Sending PII from Salesforce: Transport Encryption Is the Wrong Control

Encrypting the connection does not solve emailing personal information. What IPP 5 actually asks, and the pattern that keeps the data inside your control.

SalesforceSecurityComplianceNZ Privacy ActHISO
AUG 6 2026

Sending Email from Salesforce Securely: SMTP Is Not Encrypted by Default

SMTP is cleartext by design and TLS is opportunistic. Why Preferred Verify still sends in the clear, and what to configure so email is actually protected.

SalesforceSecuritysalesforce-adminComplianceAuthentication
AUG 5 2026

Why Filtering Salesforce Event Logs by IP Misses Most of the Incident

Salesforce splits one actor's activity across event types with different identifying fields. Why IP filtering misses the SOQL, and how to correlate safely.

SalesforceSecurityEvent MonitoringIncident Responsesf-cli
AUG 4 2026

Salesforce Winter '27 Security Readiness: The Release Updates and the Sandbox Window to Test Them

Winter '27 enforces two security changes, not the five widely listed. Three slipped to 2027 or were cancelled. The dates, what breaks, and how to test.

SalesforceSecuritysalesforce-adminComplianceIntegration
AUG 2 2026

Migrating Legacy Named Credentials Before They Become the Next Salesforce Deadline

Legacy Named Credentials mix secrets and access in one record with no permission set control. Migrate during the Winter '27 window, and how the split works.

SalesforceSecuritysalesforce-adminIntegrationLeast Privilege
AUG 1 2026

Salesforce Cancelled the Profile Permissions Retirement. Migrate Anyway.

The Spring '26 deadline that forced permission set migrations is gone. What the reversal reveals, and why the deadline was never the reason to migrate.

SalesforceSecuritysalesforce-adminLeast PrivilegeUser Management
JUL 31 2026

Salesforce Stops Supporting Incorrect Instanced URLs in API Traffic, Now Spring '27

Salesforce postponed the instanced URL enforcement to Spring '27, a third slip. Why hardcoded endpoints break, and how to control the cutover yourself.

SalesforceSecuritysalesforce-adminIntegrationAPI
JUL 29 2026

Salesforce Winter '27 Turns On Profile Filtering: What Breaks, and How to Test It First

Winter '27 enforces Profile Filtering, so users see only their own profile name. What breaks in Flows, validation rules and Apex, and how to test it early.

SalesforceSecuritysalesforce-adminUser ManagementLeast Privilege
JUL 27 2026

Salesforce Is Retiring the Email Change Verification Exemption: Set Up Authorized Email Domains Before 1 December 2026

Adopt Authorized Email Domains was cancelled. Its replacement enforces 1 December 2026. How to keep your email verification exception before it lands.

SalesforceSecuritysalesforce-adminUser ManagementCompliance
JUL 26 2026

Deployable Permission Sets for a Salesforce Delivery Team: Metadata, the CI User, and OmniStudio

Permission set XML you can deploy, how to get the right permission API names out of your own org, and how to scope the CI user and OmniStudio builder roles.

SalesforceSecurityLeast Privilegesf-cliDevOpsOmniStudio
JUL 25 2026

Salesforce Report-Export Step-Up Enforcement: The Known Issues and Gotchas Nobody Warned You About

Blocked exports, a broken Login As, and RPA jobs failing: the practitioner known issues behind Salesforce report-export step-up enforcement in July 2026.

SalesforceSecurityEvent MonitoringShieldCompliancesalesforce-admin
JUL 24 2026

Sizing a Salesforce Access Model: Team Shape, Internal vs External Admins, and What It Costs to Run

A full access model is not always the right one. How to size it to your team, flex it for external delivery partners, and what the whole thing costs to run.

SalesforceSecurityLeast Privilegesalesforce-adminDevOpsCompliance
JUL 23 2026

A Guest IP Got Flagged for Log4j: Scanner or Breach? Triage Salesforce EventLogFile in One Command

A guest Experience Cloud IP is flagged for Log4j exploitation. Scanner or real attacker? How to tell it apart from your EventLogFile logs, in one command.

SalesforceSecurityEvent MonitoringIncident ResponseExperience CloudOpen Source
JUL 23 2026

Which of Your Salesforce Connected Apps Use Less Than They're Granted? Ask Your Own Logs

Static scanners tell you what a connected app was granted, not what it uses. Here is how to measure the over-grant per object from your own EventLogFile.

SalesforceSecurityOAuthConnected AppsLeast PrivilegeOpen Source
JUL 22 2026

A Least-Privilege Access Model for the Salesforce Delivery Team: Tiers, Roles, and Where the Escalation Chain Breaks

How to tier sandboxes, layer profiles and permission set groups, and use the one fact that stops a developer escalating from a sandbox into your production org.

SalesforceSecurityLeast Privilegesalesforce-adminDevOps
JUL 20 2026

Why Your Developers Don't Need Modify All Data (And What They Actually Need Instead)

Modify All Data is org-wide read and write that does not even override field-level security. Here are the five real requests behind it, and what each one needs.

SalesforceSecurityLeast Privilegesalesforce-adminApex
JUL 18 2026

Agentforce Agent User Least Privilege: What the Wizard Grants, What Your Agent Actually Needs, and How to Audit the Gap

What the Agentforce setup wizard grants your service agent user, what it actually needs, and how to audit both before an attacker maps the gap for you.

SalesforceSecurityAgentforceLeast PrivilegeEvent Monitoringsalesforce-admin
JUL 16 2026

Locked Out After Salesforce MFA Enforcement: Recovery Paths, Temporary Codes, and the Break-Glass Account You Should Have Built

Locked out after Salesforce MFA enforcement? The recovery paths, temporary codes, Support realities, and how to build a break-glass admin account for your org.

SalesforceSecurityMFAAuthenticationsalesforce-adminIncident Response
JUL 14 2026

Audit Your Agentforce Footprint: Every Agent, Agent User, and Permission in One Pass

Inventory every Agentforce agent, agent user, and permission with sf CLI and SOQL: the exact queries to see what your agents can touch, and from where.

SalesforceSecurityAgentforcesf-clisalesforce-adminDevOps
JUL 12 2026

Post-ForcedLeak: Hardening Agentforce Against Prompt Injection (The Setup Steps Nobody Published)

ForcedLeak turned a $5 domain into an Agentforce data-exfiltration channel. The concrete Setup hardening steps to shrink your prompt-injection blast radius.

SalesforceAgentforceSecurityAIsalesforce-adminEvent Monitoring
JUL 10 2026

IPP 3A Is Live: Building New Zealand's Indirect-Collection Notice into Salesforce

New Zealand's IPP 3A now requires notice when you collect personal data indirectly. Build compliance into Salesforce with source fields, a Flow, one report.

SalesforceSecurityComplianceNZ Privacy Actsalesforce-admin
JUL 8 2026

Free Salesforce Event Monitoring: Build a Security Baseline from EventLogFile Without Shield

Salesforce gives Enterprise, Unlimited and Performance orgs free EventLogFile logs, but only for a day. How to capture them into a baseline without Shield.

SalesforceSecurityEvent Monitoringsf-cliOpen SourceDevOps
JUL 7 2026

Salesforce MFA Enforcement Update: What Was Paused, What Still Applies, and the Revised 2026 Dates

Salesforce paused its all-employee MFA enforcement over a security-key enrolment bug and revised the 2026 dates. Here is what moved and what still applies.

SalesforceMFASecurityAuthenticationCompliancesalesforce-admin
JUL 4 2026

Salesforce Data Sovereignty in New Zealand: There's No NZ Region, So What Actually Protects Your Data?

Salesforce has no New Zealand region, so your data sits offshore. What data residency, the US CLOUD Act, and NZISM actually mean for NZ gov and health orgs.

SalesforceSecurityComplianceNZISMNZ Privacy ActData Sovereignty
JUL 2 2026

Salesforce Retires the OAuth Username-Password Flow on 20 February 2027: Migrate Before Your Integrations Break

Salesforce postponed the OAuth 2.0 username-password flow retirement to 20 February 2027. What breaks, how to find affected integrations, and how to migrate.

SalesforceSecurityOAuthIntegrationsalesforce-adminAuthentication
JUN 25 2026

Salesforce Guest User Exposure: How sf-audit Grades It by Real Reachability

sf-audit now grades Salesforce guest user exposure by real UI API reachability, not just the sharing model, and adds six new external-facing security checks.

SalesforceSecuritysf-cliExperience CloudGuest UserOpen Source
JUN 23 2026

sf-audit vs sf-cli-security-audit: Two Salesforce Security CLIs Compared

Two open-source sf CLI plugins audit Salesforce security from the terminal. One is opinionated and broad, the other configurable and focused. How to pick.

SalesforceSecuritysf-clisf pluginOpen Source
JUN 21 2026

Salesforce Summer '26: The SAML Retirement and Apex Secure-by-Default Changes That Break Orgs Quietly

Two Summer '26 changes break orgs without warning: retiring single-configuration SAML stops SSO logins, and Apex now defaults to with sharing. What to check, where.

SalesforceSecuritySSOApexsalesforce-adminAuthentication
JUN 19 2026

Salesforce Security Enforcement in 2026: Every Change, Date, and What Admins Must Do

Across 2026 Salesforce turns a stack of security recommendations into hard enforcement: MFA, report step-up auth, IP blocking and more. The full list and dates.

SalesforceSecurityMFAsalesforce-adminComplianceAuthentication
JUN 17 2026

Salesforce MFA Enforcement in 2026: What Admins Must Verify and Do

Salesforce moves from contractual MFA to hard enforcement in mid-2026, with a stricter phishing-resistant bar for admins. How to verify your org and comply.

SalesforceMFASecuritySSOAuthenticationCompliance
JUN 15 2026

Why Salesforce Health Cloud Needs Its Own Security Review

Salesforce Health Cloud holds your most sensitive data, and the features that make it useful are the ones that expose it. What a security review checks.

SalesforceHealth CloudSecurityComplianceHISONZ Privacy Act
JUN 13 2026

Mapping Salesforce Security to NZISM, the NZ Privacy Act and ISO 27001

How to map Salesforce security findings to NZISM, the NZ Privacy Act, HISO 10029 and ISO 27001 using a source-verified, version-pinned control catalogue.

SalesforceSecurityComplianceNZISMNZ Privacy ActISO 27001
JUN 11 2026

Salesforce Attack Chain Detection: When Five Medium Findings Are One Critical Problem

Isolated Salesforce security findings look survivable. Attack chain detection correlates them into named multi-step scenarios, each mapped to real controls.

SalesforceSecuritysf-cliCloudCounselDevOps
MAY 9 2026

Fetching Security Metadata from Salesforce with sf CLI: Profile, PermissionSet, Role

How to retrieve Profile, PermissionSet, PermissionSetGroup, MutingPermissionSet, and Role metadata from Salesforce using sf CLI, including partial retrieval patterns for large Profile XML.

Salesforcesf-clisalesforce-adminmetadataSecurity
APR 3 2026

sf-audit v1.0: New Checks, Configurable Scoring, and Externalized Queries

The audit plugin has grown from 22 checks to 23, added four new threat surfaces, and gained a fully configurable scoring model. Here is what changed and why it matters.

SalesforceSecuritysf pluginCLITypeScriptOpen Source
MAR 31 2026

Catch Salesforce Security Gaps in One Command

Most Salesforce orgs are carrying security debt they don't know about. This plugin surfaces it in a single command.

SalesforceSecurityCLIDevOpssf plugin
MAR 31 2026

How We Built a Native sf Plugin for Salesforce Security

We had a working Python script. Here is why we rewrote it as a native sf plugin, and the design decisions that made 22 parallel security checks practical.

SalesforceArchitectureTypeScriptsf pluginSecurityOpen Source
AUG 3 2025

Mixed DML Operations: Enterprise User Provisioning Patterns for Salesforce

Master the complex challenge of mixing setup and non-setup object operations in Salesforce user provisioning workflows with production-proven patterns and error handling strategies.

SalesforceApexUser ManagementArchitectureSecurityMixed DML
NOV 1 2014

Secure APIs against XEE Attacks (XML Injection Attacks)

Learn how to secure your APIs against XML External Entity (XEE) attacks, including XML Injection and XML Expansion attacks, with practical mitigation steps for Java and RestEasy.

ArchitectureDevelopment Best PracticesProgramming LanguagesSecurityAPIXMLJava