Control the Default Records Your Users See with Scoping Rules (Beta)
Reduce noise and unnecessary searches while enhancing your users’ productivity. Based on criteria that you select, you can set rules to help your users see only records that are relevant to them. By adding a scoping rule, you can help users focus on pertinent records and prevent them from accessing records containing sensitive or inessential information. Scoping rules don’t restrict the record access that your users already have. Your users can still open and report on all records that they have access to per your org’s sharing settings
Where: This change applies to Lightning Experience in Performance and Unlimited editions.
How: Scoping rules are available for custom objects and these standard objects.
- Account
- Case
- Contact
- Event
- Lead
- Opportunity
- Task
For information on enabling this feature, contact Salesforce. You can create and modify scoping rules using the Tooling or Metadata API.
Control the Default Records Your Users See with Scoping Rules (Beta) (salesforce.com)
Control Access to Sensitive Data with Restriction Rules (Generally Available)
Secure your data and boost productivity by permitting your users to see only the records necessary for their job function. Create restriction rules to control which subset of records you allow specified groups of users to see. Restriction rules are available for custom objects, contracts, tasks, events, time sheets, and time sheet entries. This feature, now generally available, includes some changes since the last release. You can now create and manage restriction rules in Setup as well as with Tooling and Metadata APIs.
Where: This change applies to Lightning Experience in Enterprise, Performance, Unlimited, and Developer editions.
How: To create a restriction rule, navigate to Object Manager in Setup. Select the object that you want to add a restriction rule for. Click Restriction Rules. Name and describe the rule and activate it. Select a user field and choose filter settings to determine which users the rule applies to. Then, select a record field and choose filter settings to determine which records are accessible.
Control Access to Sensitive Data with Restriction Rules (Generally Available) (salesforce.com)
Hide More Personal Information Fields from External Users
To prevent external users, such as portal or partner users, from viewing personal information in your user records, enable the Enhanced Personal Information Management permission. Salesforce then blocks view and edit access to 20 fields that are considered personal information. You can configure which fields you consider personal information from User Management Settings. This permission replaces the less-configurable Hide Personal Information setting, which will be retired in the Winter ’23 release.
Where: This change applies to Lightning Experience in Enterprise, Performance, Unlimited, and Developer editions.
Why: When you enable the Enhanced Personal Information Management permission, these fields are masked to external users.
- About Me
- Address
- Alias
- Company Name
- Department
- Division
- Email Sender Address
- Email Sender Name
- Email Signature
- Employee Number
- Extension
- Fax
- Manager
- Mobile
- SAML Federation ID
- Phone
- Title
- User Photo badge text overlay
- Username
How: You can click to access a user record field directly from this org permission in User Management Settings. Add or remove PersonalInfo from the field’s Compliance Categorization area. In the Winter '23 release, this setting will be enforced and the Hide Personal Information setting will be retired.
Hide More Personal Information Fields from External Users (salesforce.com)
Sharing
Find out how to hide fields containing personal information from external users with an enhanced user management setting. Manage access to sensitive data on contracts, tasks, events, time sheets, and time sheet entries. And limit the default records that your users see so that they only see what’s necessary.
- Hide More Personal Information Fields from External Users
To prevent external users, such as portal or partner users, from viewing personal information in your user records, enable the Enhanced Personal Information Management permission. Salesforce then blocks view and edit access to 20 fields that are considered personal information. You can configure which fields you consider personal information from User Management Settings. This permission replaces the less-configurable Hide Personal Information setting, which will be retired in the Winter ’23 release. - Control Access to Sensitive Data with Restriction Rules (Generally Available)
Secure your data and boost productivity by permitting your users to see only the records necessary for their job function. Create restriction rules to control which subset of records you allow specified groups of users to see. Restriction rules are available for custom objects, contracts, tasks, events, time sheets, and time sheet entries. This feature, now generally available, includes some changes since the last release. You can now create and manage restriction rules in Setup as well as with Tooling and Metadata APIs. - Control the Default Records Your Users See with Scoping Rules (Beta)
Reduce noise and unnecessary searches while enhancing your users’ productivity. Based on criteria that you select, you can set rules to help your users see only records that are relevant to them. By adding a scoping rule, you can help users focus on pertinent records and prevent them from accessing records containing sensitive or inessential information. Scoping rules don’t restrict the record access that your users already have. Your users can still open and report on all records that they have access to per your org’s sharing settings
Share Resources with Browser Extensions
Add browser extensions to your cross-origin resource sharing (CORS) list to allow requests for Salesforce REST resources. Previously, the CORS allowlist supported only websites and IP addresses. For example, you can now allow an appointment management browser extension to view and work with your Salesforce records. Browser extensions that aren't on your CORS allowlist are blocked from requesting resources.
Where: This change applies to Salesforce Classic and Lightning Experience in Developer, Enterprise, Performance, and Unlimited Editions. It also applies to Professional Edition with API access enabled.
How: From Setup, in the Quick Find box, enter CORS, and then select CORS.
Share Resources with Browser Extensions (salesforce.com)
Prevent Data Loss with Backup and Restore (Generally Available)
Protect your organization from permanent data loss and corruption by automatically generating backups. With just a few clicks, your data is backed up and can be restored quickly in the event of integration errors, malicious attempts, or incorrect data updates. Use Backup & Restore to prevent data loss, recover from data incidents quickly, and simplify your overall data management strategy.
Where: Backup and Restore is available for Lightning Experience in Professional, Enterprise, Unlimited, and Performance editions.
Who: Backup & Restore requires a platform license and a permission.
Why: With Backup & Restore, you can protect your organization against incorrect data updates, integration execution issues, malicious actors, and ransom ware attacks. Backup & Restore provides:
- Custom and Standard Object backups
- Daily incremental backups
- Backup in the same region
- Backup-to-Current-State comparisons
- Record previews before restoring
- Restoration to original org
- Backup dashboard & statistics
- Run logs on which to build custom triggers and flows
How: When you log in to Backup & Restore, the dashboard displays all recent backups and API activity. If it’s your first time using Backup & Restore, use the Settings tab to provision resources, connect to Backup & Restore by enabling OAuth, or test end-to-end connectivity. These are settings you set just once during setup.
- To create a backup policy, on the Backup tab, click the Data tile, and click Next. You’ll see all the objects that can be backed up in this tab. Click Save after activating and selecting Related Objects.
- To restore a backup, on the Restore tab, click the Data tile, and click Next. Select the backup you want to restore from, then click Restore and then Confirm.
- To get information on previous backup and restore activity, click the Logs tab.
Prevent Data Loss with Backup and Restore (Generally Available) (salesforce.com)
Other Security Changes
The CORS allowlist now supports browser extension requests to Salesforce REST resources. Prevent data loss and recover quickly from incorrect data updates or integration errors with the new Backup and Restore feature.
- Prevent Data Loss with Backup and Restore (Generally Available)
Protect your organization from permanent data loss and corruption by automatically generating backups. With just a few clicks, your data is backed up and can be restored quickly in the event of integration errors, malicious attempts, or incorrect data updates. Use Backup & Restore to prevent data loss, recover from data incidents quickly, and simplify your overall data management strategy. - Share Resources with Browser Extensions
Add browser extensions to your cross-origin resource sharing (CORS) list to allow requests for Salesforce REST resources. Previously, the CORS allowlist supported only websites and IP addresses. For example, you can now allow an appointment management browser extension to view and work with your Salesforce records. Browser extensions that aren't on your CORS allowlist are blocked from requesting resources.
Other Security Changes (salesforce.com)
Explore Metric Data with Detail View Filters
Quickly find information you need by applying filters to metric detail pages.
Where: Security Center is available in Enterprise, Performance, Unlimited, and Developer editions as an add-on subscription.
How: To change which results are displayed on a metric detail page, below the summary graph, click the filter button. Choose your filter conditions, and click Apply to see the filtered metric data.
Add New Post ‹ Application Perfection — WordPress
Create Alerts for Changes to Your Security Configuration
Automate security monitoring by setting up in-app and email alerts for conditions of your choosing. Indicate what changes you want to be alerted of, how you want to be alerted, and who receives the alert.
Where: Security Center is available in Enterprise, Performance, Unlimited, and Developer editions as an add-on subscription.
Who: This change is available to customers who purchase Security Center and Event Monitoring add-on subscriptions.
How: From the Security Center app in your parent tenant, click the Alert Settings tab. Click New Alert, and follow the instructions to define your alert details like triggers and thresholds. For example, receive an alert if the number of users with the Modify All Data permission in any tenant reaches more than five.
Create Alerts for Changes to Your Security Configuration (salesforce.com)
Monitor Security Threats with Centralized Threat Detection (Generally Available)
The Threat Detection integration powered by Event Monitoring for Security Center is now generally available. Let machine learning identify and provide data on four types of threats across your connected tenants in real time.
Where: Security Center is available in Enterprise, Performance, Unlimited, and Developer editions as an add-on subscription.
Who: This change is available to customers who purchase Security Center and Event Monitoring add-on subscriptions.
How: From the Security Center dashboard in your parent tenant, click Threat Detection. Below the 30-day summary graph, choose a date. To see the details of a detected event, click the Threat Identifier value. The four supported security threats are: Credential Stuffing, API Anomaly, Session Hijacking, and Report Anomaly.
Monitor Security Threats with Centralized Threat Detection (Generally Available) (salesforce.com)