Users can now register biometric built-in authenticators, such as Touch ID, Face ID, and Windows Hello. You can monitor which users register built-in authenticators and when they use them. As you prepare for the multi-factor authentication (MFA) requirement, check out the MFA Rollout Pack for customizable templates. Also, users are no longer subject to MFA challenges in Salesforce when they log in through an authentication provider that supports single sign-on. And you can track enforced MFA challenges with four new verification history fields in users reports. For increased security, configure forced authentication when Salesforce is acting as a SAML identity provider. Salesforce now prevents users from logging in with a username and password as GET query string parameters to the login URL. Upgrade to Identity Connect 7.1 as soon as possible because Salesforce no longer supports downloads for Identity Connect 2.1 and Identity Connect 3.0.X.X. For improved functionality, customize the way your JIT handler processes user information, include refresh tokens in the OAuth 2.0 user-agent flow, and authorize additional access to Salesforce CDP data.

  • Trailblazer.me Supports New Languages
    To improve accessibility for our global Trailblazer community, Trailblazer.me now supports 11 more languages: Danish, Dutch, Finnish, Italian, Korean, Norwegian, Russian, Simplified Chinese, Spanish (Spain), Swedish, and Traditional Chinese.
  • Streamline Identity Verification with Built-In Authenticators (Beta)
    With new support for biometric methods, verifying your identity in Salesforce just got even easier. Users can register biometric built-in authenticators, such as Touch ID, Face ID, and Windows Hello. Anytime users are challenged to verify their identity, including multi-factor authentication and device activations, they’re prompted to use their built-in authenticator.
  • Get Users Ready for Multi-Factor Authentication with Change Management Resources
    As you prepare for the multi-factor authentication (MFA) requirement that goes into effect on February 1, 2022, check out the MFA Rollout Pack. It provides customizable planning and change management templates to help you roll out MFA to your users.
  • MFA Challenges for Authentication Provider Single Sign-On Logins Are No Longer Enforced
    By default, users who log in to Salesforce through an authentication provider that supports single sign-on (SSO) are no longer subject to multi-factor authentication (MFA) challenges in Salesforce. To restore MFA challenges for those users, you can update the session security levels for their assigned profiles.
  • Verify Logins in Users Reports
    Four new verification history fields in users reports let you view user login verification data. Use these fields in combination with login history fields to identify which user logins have multi-factor authentication (MFA) challenges enforced.
  • Require Users to Reauthenticate When Accessing Service Providers with Single Sign-On
    To protect sensitive resources, you can now configure forced authentication when Salesforce is acting as a SAML identity provider. With forced authentication, users who are already logged in to Salesforce must reenter their credentials when trying to access a third-party service provider. After setting up this feature, you can use the identity provider event log to monitor when users have been logged out due to forced authentication.
  • Login Credentials Using URL Query Strings Are Disabled (Release Update)
    With this update, users can no longer log in to Salesforce by using a username and password as URL query string parameters to the login URL. Users who try to do so are redirected to the login page. This update improves security.
  • Customize How Just-in-Time Provisioning Handlers Process Attributes in SAML Assertions
    If you’re configuring just-in-time (JIT) provisioning with a custom Apex handler, and your single sign-on (SSO) identity provider sends encrypted SAML assertions, Salesforce now passes the decrypted assertion to your JIT handler. The previous process sometimes limited the JIT handler from accessing certain user attributes. The decrypted assertion is stored as a value with the key Sfdc.SamlAssertion. With access to the decrypted assertion, you can modify the way your JIT handler processes the assertion to make sure no attribute gets left behind.
  • Upgrade to Identity Connect 7.1.1
    Identity Connect 7.1.1 offers extensive security enhancements. As of the Winter ’22 release, you can no longer download Identity Connect 2.1 and Identity Connect 3.0.X.X. We recommend that you upgrade to Identity Connect 7.1.1 as soon as possible.
  • Give Authorized Access to Salesforce CDP Data
    To authorize additional access to Salesforce CDP data, you can assign a connected app two new OAuth scopes. With the Perform ANSI SQL queries on Salesforce CDP data OAuth scope, the connected app can perform ANSI SQL queries of Salesforce CDP data on behalf of the user. The Manage Salesforce CDP profile data OAuth scope gives the connected app access to Salesforce CDP REST API data to manage profile records.
  • OAuth 2.0 User-Agent Flow Supports mobileauth.salesforce.com/analytics Redirect URL for Refresh Tokens
    The OAuth 2.0 user-agent flow now supports refresh tokens when the scope=refresh_token is included in the request and the redirect URL is https://mobileauth.salesforce.com/analytics/oauth/done.

Salesforce Identity for Your Employees

Privacy Preference Center