Grant Access Based on Activated User Sessions for Permission Set Groups
To grant your users only the access that they need when they need it, combine the management power of permission set groups with session-based access control. Create a session-based permission set group to grant access to permission sets during an activated user session. Previously, you created individual session-based permission sets, but now you can set sessions at the permission set group level as well.
Where: This change applies to Lightning Experience and Salesforce Classic in Professional, Enterprise, Performance, Unlimited, and Developer editions.
Why: For example, you have a customized Salesforce app that accesses confidential information. For security reasons, you want to limit user access to a predetermined length of time. Some users, such as a team manager, require expanded access for the same length of time. You can create a permission set group that includes the different permission sets required for the confidential access. You can create a flow or use the API to create custom logic to activate the session-based permission set group. In this example, the session-based permission set group activates only when the manager-level users authenticate into your environment using a token. When the token expires, the users must reauthenticate to access the application again.
How: To create a session-based permission set group, select Session Activation Required on the Permission Set Group create page. Then, activate the session for the permission set group using a flow or the SessionPermSetActivation SOAP API object.
Profiles and Permissions
Get the benefits of expanded profile and permission management. Use the power of permission set groups to configure session-based access control. Create custom profiles using the API instead of cloning existing profiles.
https://help.salesforce.com/s/articleView?id=release-notes.rn_forcecom_permissions.htm&release=234&type=5
Control the Default Records Your Users See with Scoping Rules (Beta)
Reduce noise and unnecessary searches while enhancing your users’ productivity. Based on criteria that you select, you can set rules to help your users see only records that are relevant to them. By adding a scoping rule, you can help users focus on pertinent records and prevent them from accessing records containing sensitive or inessential information. Scoping rules don’t restrict the record access that your users already have. Your users can still open and report on all records that they have access to per your org’s sharing settings
Where: This change applies to Lightning Experience in Performance and Unlimited editions.
How: Scoping rules are available for custom objects and these standard objects.
- Account
- Case
- Contact
- Event
- Lead
- Opportunity
- Task
For information on enabling this feature, contact Salesforce. You can create and modify scoping rules using the Tooling or Metadata API.
Control Access to Sensitive Data with Restriction Rules (Generally Available)
Secure your data and boost productivity by permitting your users to see only the records necessary for their job function. Create restriction rules to control which subset of records you allow specified groups of users to see. Restriction rules are available for custom objects, contracts, tasks, events, time sheets, and time sheet entries. This feature, now generally available, includes some changes since the last release. You can now create and manage restriction rules in Setup as well as with Tooling and Metadata APIs.
Where: This change applies to Lightning Experience in Enterprise, Performance, Unlimited, and Developer editions.
How: To create a restriction rule, navigate to Object Manager in Setup. Select the object that you want to add a restriction rule for. Click Restriction Rules. Name and describe the rule and activate it. Select a user field and choose filter settings to determine which users the rule applies to. Then, select a record field and choose filter settings to determine which records are accessible.
Hide More Personal Information Fields from External Users
To prevent external users, such as portal or partner users, from viewing personal information in your user records, enable the Enhanced Personal Information Management permission. Salesforce then blocks view and edit access to 20 fields that are considered personal information. You can configure which fields you consider personal information from User Management Settings. This permission replaces the less-configurable Hide Personal Information setting, which will be retired in the Winter ’23 release.
Where: This change applies to Lightning Experience in Enterprise, Performance, Unlimited, and Developer editions.
Why: When you enable the Enhanced Personal Information Management permission, these fields are masked to external users.
- About Me
- Address
- Alias
- Company Name
- Department
- Division
- Email Sender Address
- Email Sender Name
- Email Signature
- Employee Number
- Extension
- Fax
- Manager
- Mobile
- SAML Federation ID
- Phone
- Title
- User Photo badge text overlay
- Username
How: You can click to access a user record field directly from this org permission in User Management Settings. Add or remove PersonalInfo from the field’s Compliance Categorization area. In the Winter '23 release, this setting will be enforced and the Hide Personal Information setting will be retired.
Sharing
Find out how to hide fields containing personal information from external users with an enhanced user management setting. Manage access to sensitive data on contracts, tasks, events, time sheets, and time sheet entries. And limit the default records that your users see so that they only see what’s necessary.
Add and Remove Permission Set License Assignments Faster
Save time by assigning multiple users to a permission set license together or by removing multiple users all at once. On each permission set license detail page, you can select multiple users to complete bulk assignment operations. Previously, you added or removed users individually from each user’s detail page.
Where: This change applies to Lightning Experience and Salesforce Classic in Professional, Enterprise, Performance, Unlimited, and Developer editions.
How: Before you remove the permission set license, you must remove the related assigned permissions from the user. Then, from Setup, in the Quick Find box, enter Company Information, and select Company Information. Scroll down to the permission set licenses related list, and click the name of the permission set license that you want to assign users to or remove users from. To see and remove current assignments, click View Users. To assign users, click Assign Users.
See More Information About Permission Set Licenses
See key details about your permission set licenses on the Company Information Setup page. In the permission set licenses related list, you get a snapshot of your licenses, their expiration dates, and the number of remaining seats. On each license’s detail page, you now see which user, object, and custom permissions are available for the license. From this detail page, you can also view and manage user assignments.
Where: This change applies to Lightning Experience and Salesforce Classic in Professional, Enterprise, Performance, Unlimited, and Developer editions.
How: From Setup, in the Quick Find box, enter Company Information, and then select Company Information. Scroll down to the Permission Set Licenses related list for a quick glance at your licenses. For more details about a specific permission set license and to manage assignments, click the license name.
Get Ready for the Future Requirement to Enable Multi-Factor Authentication (MFA)
On February 2, 2021, we announced a future requirement for all customers to enable multi-factor authentication (MFA) for their Salesforce products. To satisfy the MFA requirement, all your internal users who log in to Salesforce through the user interface must use MFA. You can turn on MFA directly in Salesforce or use your single sign-on (SSO) provider’s MFA service. Salesforce MFA is available at no extra cost.
Where: This change applies to Lightning Experience, Salesforce Classic, and all Salesforce mobile apps in all editions.
When: Beginning February 1, 2022, per the Salesforce Trust and Compliance Documentation, all Salesforce customers are contractually required to use MFA for direct and SSO logins to Salesforce products. We encourage you to begin planning now and implement MFA as soon as possible.
Why: The global threat landscape is constantly evolving, and the types of attacks that can cripple a business and exploit consumers are on the rise. A key part of your security strategy is safeguarding access to your Salesforce user accounts. But on their own, user credentials don’t provide sufficient protection against threats like phishing attacks, man-in-the-middle attacks, and credential stuffing. That’s where MFA comes in. It’s one of the easiest, most effective ways to prevent unauthorized account access and safeguard your business and your customers’ data.
How: MFA requires users to prove they’re who they say they are by providing two or more pieces of evidence—or factors—when they log in. One factor is something the user knows, such as their username and password combination. Other factors are verification methods that the user has in their possession, such as the Salesforce Authenticator app or a physical security key. By tying logins to multiple, different types of factors, it’s much harder for a bad actor to access your Salesforce environment. To learn more about MFA, watch the How MFA Works to Protect Account Access video.
We’re here to help you get ready for the MFA requirement. To get started, check out the Multi-Factor Authentication Assistant. In Lightning Experience, from Setup, in the Quick Find box, enter MFA, and then select Multi-Factor Authentication Assistant. And to get customizable templates for rollout planning and change management, download the MFA Rollout Pack.
General Enhancements
Enable Multi-Factor Authentication at no extra cost. See more information about permission set licenses and add and remove them more quickly.
- Get Ready for the Future Requirement to Enable Multi-Factor Authentication (MFA)
On February 2, 2021, we announced a future requirement for all customers to enable multi-factor authentication (MFA) for their Salesforce products. To satisfy the MFA requirement, all your internal users who log in to Salesforce through the user interface must use MFA. You can turn on MFA directly in Salesforce or use your single sign-on (SSO) provider’s MFA service. Salesforce MFA is available at no extra cost. - Keep Working with Tab-Focused Dialogs (Release Update)
In Lightning console apps, dialogs no longer stop you from interacting with the rest of the UI. This release update limits the focus of dialogs triggered by a workspace tab or subtab to only the tab that triggered it. This update was first made available in Winter ’20 and was scheduled to be enforced in Spring ’22, but we postponed the enforcement date to Spring ’24. - See More Information About Permission Set Licenses
See key details about your permission set licenses on the Company Information Setup page. In the permission set licenses related list, you get a snapshot of your licenses, their expiration dates, and the number of remaining seats. On each license’s detail page, you now see which user, object, and custom permissions are available for the license. From this detail page, you can also view and manage user assignments. - Add and Remove Permission Set License Assignments Faster
Save time by assigning multiple users to a permission set license together or by removing multiple users all at once. On each permission set license detail page, you can select multiple users to complete bulk assignment operations. Previously, you added or removed users individually from each user’s detail page. - Solve Cross-Cloud Use Cases with Salesforce Solution Kits
Salesforce solution kits help you implement solutions to complex, cross-cloud use cases. Each solution kit includes recommendations for specific products, configurations, and best practices.