Require the View All Lookup Record Names Permission

To better protect your Salesforce org’s data, you can restrict who can view record names in lookup fields and system fields, such as Created By and Last Modified By. If you enable the Require permission to view record names in lookup fields setting, users need Read access to these records or the View All Lookup Record Names permission to view this data. Previously, this behavior was set to be enforced in a release update, but instead the functionality is now an opt-in setting so you can enable it when it best suits your org.

Where: This change applies to Lightning Experience and Salesforce Classic in all editions.

Why: Admins have more control over what users see in records. If the Require permission to view record names in lookup fields setting isn’t enabled, users can view record names in lookup fields without Read access to those records.

After the Require permission to view record names in lookup fields setting is enabled, in Lightning Experience, users who don’t have Read access or the View All Lookup Record Names permission see the lookup field labels, but not the data in the fields.

In Salesforce Classic, users who don’t have Read access or the View All Lookup Record Names permission see an underscore in system user lookup fields. They also see the record ID in custom user lookup and non-user lookup fields.

How: To enable this setting, from Setup, in the Quick Find box, enter Sharing Settings, and then select Sharing Settings. Click Edit in the Organization-Wide Defaults area, then select Require permission to view record names in lookup fields.

Admins can enable the View All Lookup Record Name permission in custom profiles or permission sets. Only enable this permission for users who must see record names in all lookup and system fields, regardless of sharing settings. This permission only applies to lookup record names in list views and record detail pages.

https://help.salesforce.com/s/articleView?id=release-notes.rn_forcecom_general_lookup_setting.htm&release=230&type=5


General Setup

Control who can view record names in lookup fields with a new setting instead of a release update.

https://help.salesforce.com/s/articleView?id=release-notes.rn_forcecom_custom_general.htm&release=230&type=5


Sharing

Grant access to records with manual sharing in Lightning Experience and create more roles in your Salesforce org.

https://help.salesforce.com/s/articleView?id=release-notes.rn_forcecom_sharing.htm&release=230&type=5


Create More Roles

In Salesforce orgs created in Spring ’21 or later, you can create up to 5,000 roles. In existing orgs, the default limit hasn’t changed. You can create up to 500 roles and can contact Salesforce Customer Support to increase this limit. Keep in mind that to improve performance, it’s best to set up roles based on data access and eliminate any roles that aren’t needed.

Where: This change applies to Lightning Experience and Salesforce Classic in Professional, Enterprise, Performance, Unlimited, and Developer editions.

https://help.salesforce.com/s/articleView?id=release-notes.rn_forcecom_sharing_roles.htm&release=230&type=5


Share Records with Manual Sharing

With manual sharing in Lightning Experience, you now can share records and manage record shares in a new streamlined interface. Previously, you switched to Salesforce Classic to give specific users and user groups access to records.

Where: This change applies to Lightning Experience in Professional, Enterprise, Performance, Unlimited, and Developer editions.

When: This functionality is available on a rolling basis starting in the Spring ’21 release and is available to all customers by February 27, 2021.

Why: Click Sharing on the record that you want to share. In the Share window, you can manage who the record is shared with and share any associated records. Manual shares are available only for accounts, opportunities, cases, contacts, leads, and custom objects.

https://help.salesforce.com/s/articleView?id=release-notes.rn_forcecom_manual_sharing_lex.htm&release=230&type=5


Profiles and Permissions

We made changes to the Read Only profile that you’ll want to know about. And, we now have integration permission sets.

  • Convert the Read Only Standard Profile to a Custom Profile (Update)
    This update converts the Read Only standard profile to a custom profile. After the update is enforced, you can edit permissions in this profile as your business needs require.
  • The Read Only Profile Is No Longer Available in New Salesforce Orgs
    Salesforce orgs created in Spring ’21 and later don’t have the Read Only standard profile. If you want to assign users read-only permissions, we recommend that you start with the Minimum Access standard profile as a least-privilege profile base. Then you can assign custom permission sets to grant users the read access required for your business needs.
  • Use Integration Permission Sets to Exchange Data with Integration Partners
    Integration permission sets define the scope of data access by Salesforce integration-related features and services. Depending on the integration features, Salesforce can predefine the integration permission sets so that they aren’t editable in your Salesforce org. Or, an integration permission set can have no initial permissions so that you have full control for your org. An integration permission set can also come with on-premises permissions that you can modify for your org.

https://help.salesforce.com/s/articleView?id=release-notes.rn_forcecom_profiles_perms.htm&release=230&type=5


Other Security Changes

Improve load times for authenticated site visitors through a new Visualforce page caching option. Update your site guest users to the latest license. Secure HTTPS connections are enforced for third-party domain connections, and you can decide what types of cookies are allowed on your Salesforce Sites.

  • Cache Your Site’s Visualforce Pages for Authenticated Users
    Improve your authenticated users’ experience by caching your site’s Visualforce pages on their web browsers to reduce page load times. By default, proxy servers cache publicly available pages only for unauthenticated guest users. Now you can disable that proxy server caching and determine whether to cache each page on the end user’s web browser instead. The page-specific caching applies to authenticated and unauthenticated users.
  • Update Site Guest Users to the Latest License
    Some Experience Cloud sites and Salesforce Sites created before the Spring ’21 release can have an outdated license associated with the site’s guest users. If your site’s guest users have the standard guest user license, update them to the provisioned guest user license, which gets updated automatically and has more consistent permissions.
  • Secure HTTPS Connections to Third-Party Domains Are Enforced
    HTTPS connections are required to connect to third-party domains, and HTTP connections are no longer permitted. The Require secure connections (HTTPS) for all third-party domains setting on the Session Settings Setup page was removed because it can’t be disabled. The Require secure connections (HTTPS) setting was also removed because it was previously enabled and can’t be disabled.
  • Set Preferences for Allowed Cookies for Salesforce Sites
    A new Salesforce Sites setting lets you decide what types of cookies are allowed on your site by default.
  • View Source IP Addresses in Your Private Connect Inbound Connections
    You can now easily view the ranges of source IP addresses allocated to your inbound network connections by the Salesforce Transit VPC in your cloud provider, such as AWS. Use these IP addresses with Salesforce security features to get more protection. For example, you can specify that users can log in from these IP addresses without receiving a login challenge. Or add these source IP addresses to the list of restricted addresses that users can access Salesforce from.
  • Private Connect Is HIPAA Compliant
    Your Health Insurance Portability and Accountability Act (HIPAA)-regulated Salesforce customers can now use Private Connect and maintain HIPAA compliance by signing the Salesforce Business Associate Addendum (BAA). Regulated Health Care Salesforce customers can rest assured that their customer data, including electronic protected health information (ePHI), is accessible exclusively through the private internet.
  • Add More Trusted Domains for Inline Frames
    You can now add up to 512 domains where you allow iframes of your Visualforce pages, site pages, surveys, or embedded services. Previously, the limit was 256 domains.

https://help.salesforce.com/s/articleView?id=release-notes.rn_security_other_changes.htm&release=232&type=5


Security Center

New date range fields on metric detail pages give you flexibility over which metric details you see at once. And Security Center now integrates with Event Monitoring Threat Detection (beta). You can see the total number of events per threat type, along with detailed information about each threat event without leaving the Security Center app. Threat event metrics update in near real time, offering you a more timely and complete view of your security posture.

https://help.salesforce.com/s/articleView?id=release-notes.rn_security_sc.htm&release=232&type=5


Salesforce Shield

Use the new Real-Time Event Monitoring Permission Set Event (generally available) to monitor permission changes and even make Transaction Security policies for user permissions. The APITotalUsage event log file type helps you track unused API versions. And the new USER_TYPE field helps identify if users associated with events are authenticated or guest users. Shield Platform Encryption now supports the User Email field (beta) and contact point fields.

  • Shield Platform Encryption
    By popular demand, Shield Platform Encryption for User Email (beta) offers an extra layer of protection for user emails used throughout your Salesforce deployment. You can also encrypt addresses, email addresses, and phone numbers for the points of contact associated with individual and person accounts.
  • Event Monitoring
    Some Event Log File types now include a USER_TYPE field to help you identify whether users associated with events are authenticated or guest users. The new API Total Usage event type gives admins insights into which orgs use retired API versions. And, use the Security Center app to review metrics about Threat Detection events (beta).

https://help.salesforce.com/s/articleView?id=release-notes.rn_security_shield.htm&release=232&type=5


Domains

Deploy a My Domain, and enable enhanced domains to meet the latest browser requirements. Improve Search Engine Optimization (SEO) by redirecting your site traffic to your custom domain. Secure HTTPS connections are enforced and HSTS preloading is recommended for your domains.

  • Enable Enhanced Domains (Update)
    To comply with the latest browser and security standards, enable enhanced domains on your Salesforce org’s My Domain. With enhanced domains, your company-specific My Domain name is included in your URLs, including Salesforce Sites and Experience Cloud sites. Consistent domain formats improve the user experience and standardize URLs for use in custom code and API calls. Salesforce enhanced domains also comply with the latest browser requirements, allowing your users to access Salesforce using browsers that block third-party cookies. Because this update affects application URLs, including Experience Cloud sites, Salesforce Sites, and Visualforce pages, we recommend that you enable enhanced domains before it’s enforced in Summer ’22.
  • Redirect Site Traffic to Your Custom Domain
    Improve your custom domain’s Search Engine Optimization (SEO) by redirecting requests for your site’s system-managed URL to the HTTPS custom domain, such as https://example.com, that serves the site. System-managed site base URLs end in .force.com.my.salesforce-sites.com, or .my.site.com. Redirecting traffic from these URLs to your branded domain improves the user experience and helps search engines properly rank your custom domain.
  • Secure HTTPS Connections Are Enforced in Domains
    To better protect your data, Salesforce disabled HTTP-only domains. Settings that enforce HTTPS connections or upgrade HTTP requests were enabled and then removed in Summer ’21 because they’re required and enforced by default. We also renamed our non-HTTPS domain configuration option to reflect that it’s for temporary use only.
  • Allow Only Secure Connections to Your Domain with HSTS Preloading
    As a security best practice, enable and submit your domain for HTTP Strict Transport Security (HSTS) preloading so that HTTPS connections are always used in supported browsers. Currently, all HTTP requests are redirected to HTTPS. However, connections are still vulnerable during that redirection.
  • Deploy a My Domain (Previously Released Update)
    To use the latest features and comply with browser requirements, all Salesforce orgs must have a My Domain. Deploy one, or we assign one for you based on your org ID. Because your My Domain affects all application URLs, we recommend that you test and deploy a My Domain before this update is enforced in Winter ’22. This update was first made available in Winter ’21.

https://help.salesforce.com/s/articleView?id=release-notes.rn_security_domains.htm&release=232&type=5


Privacy Preference Center