Spring 20 Summary
Another massive set of permissions changes in the Spring 20 release. Over 20 new features giving you increased control over how users access the platform and what they can do on the platform. Permission set groups in GA, more control over external org wide defaults. Custom settings and much, much more
Winter 20 highlights
- Permission Set Groups: Assign users a single permission set group instead of multiple permission sets.
- Install Even More Custom Objects in Your Org: raised the total hard limit for custom objects in an org to 3,000 (up from 2,500 in the previous release) so that you can install more custom objects from packages.
- Check a Field’s References and Find Reports Using It (Generally Available): With the click of a button, view the references to a custom field before you edit it, such as references in a formula, layout, or Apex class.
- Secure Guest Users’ Sharing Settings: When you enable the Secure guest user record access setting, you set guest users’ org-wide defaults to Private for all objects. This setting also restricts the way you can share records with guest users and lets you create new guest user sharing rules.
- Safeguard Your Data by Setting External Access Levels for More Standard Objects (Generally Available): You can now set external access levels for many more standard objects. Select more restrictive access for external users without changing the default access level for internal users.
- Keep Sharing Records When Migrating to Enterprise Territory Management: If you’re migrating to Enterprise Territory Management, you can keep your original territory sharing records so that your sales team can continue working.
Winter 20 Summary
Well its been a big release. Better control over external user access to data through controlling the org wide defaults on external objects. Permission set groups in Beta. Understand where a field is used throughout your org. They upped the limit from 2500 to 3000 custom objects and the reporting around custom object usage. Improved domain name setting, API monitoring, Sharing settings and much much more.
Check a Field’s References and Find Reports Using It (Generally Available)
With the click of a button, view the references to a custom field before you edit it, such as references in a formula, layout, or Apex class. On a custom field’s detail page, click Where is this used? to see where a field is used and where changes to the field appear. Use this information to communicate changes to others who use the field in a formula or other context. In this release, we added support for reports.
Where: This change applies to Lightning Experience and Salesforce Classic in Professional, Enterprise, Performance, and Unlimited editions.
Who: Admins with the View Setup permission can check where a custom field is used.
The list can include these references.
- Validation rule
- Layout
- Formula field
- Visualforce page
- Apex class
- Apex trigger
- Email template (Salesforce Classic, text based)
- Field set
- Flow (query)
- Lightning component markup (attr)
- Process Builder (criteria)
- URL button (formula)
- Lightning page (related list single)
- Lookup filter (lookup and master detail)
- Reports (column
Click a reference label to view the settings for the layout, formula, or other reference. Reference labels link to more information only if there is a known settings page for the reference. For example, a report name links to the report settings. But, a criteria formula created within a flow does not link to the flow settings.
Within a subscriber org, references in a managed package aren’t included in the list of results. For example, you have a number field referenced in a formula. If you add the field to a package and install the package in a subscriber org, the subscriber org’s field reference detail page doesn’t show that this number field is referenced in a formula field.
However, new references created after installing the managed package in the subscriber org do appear. For example, after you install the managed package and you add the number field to another formula in the subscriber org, the new reference appears.
Do More with the Optimizer App
The Optimizer App now has even more capabilities to enhance your Salesforce org’s implementation. Use two new features to schedule automatic runs and view org metric history and access seven new metrics to improve security.
Where: This change applies to Lightning Experience in Professional, Enterprise, Performance, Unlimited, and Developer editions.
Who: Users must have the Customize Application, Modify All Data, and Manage Users user permissions to access the Optimizer App.
Why:
We added two new features:
- Schedule Run: Save yourself time by setting the Optimizer App to automatically run once a month, behind the scenes.
- Org Metric History: Get a high-level overview of how actions have affected the limits on your org’s file storage, static resources, and data storage.
We also added seven new metrics to help evaluate and give expert recommendations on the security of your org. Ensure that your Salesforce org’s data is secure by following security configuration best practices.
- Profile Assignments
- Critical Permission Assignments
- Release Updates Pending Review
- Insecure Community Sharing Settings
- Insecure Default External Access Levels
- Sharing Rules for All External Users
- Public Groups and Queues with Guest Users
How: From Setup, in the Quick Find box, enter Optimizer, then select Optimizer.
Release Updates
Salesforce periodically releases updates that improve the performance, logic, security, and usability of Salesforce, but which can affect your existing customizations. Find these important updates in the Release Updates node in Setup.
The Release Updates page provides a list of updates that affect your org. Each update includes step-by-step actions for you to take. To ensure a smooth transition, many release updates have test runs available. Use the test run option to enable and disable an update as often as needed before the "Complete Steps By" date so that you can evaluate its impact on your org.
https://help.salesforce.com/s/articleView?id=release-notes.rn_ru.htm&release=228&type=5
Find Security Alerts in the Same Location as Release Updates
When you look for security alerts that affect your Salesforce org, find them in the Release Updates node. Previously, security alerts resided in a separate location.
Where: This change applies to Lightning Experience and Salesforce Classic in all editions, except Database.com.
How: From Setup, in the Quick Find box, enter Release Updates. In the Release Updates page, you can find security alert cards. Security alerts functionality remains the same.
https://help.salesforce.com/s/articleView?id=release-notes.rn_sa_change.htm&release=228&type=5
View Org Changes in One Location with Release Updates (Generally Available)
In case you missed it in the last release, Release Updates offers a more detailed view of information previously found in Critical Updates and Security Alerts. Find all of your updates and alerts in an improved format. No more clicking through several locations to review important update information for your Salesforce org.
Where: This change applies to Lightning Experience and Salesforce Classic in all editions, except Database.com.
How: From Setup, in the Quick Find box, enter Release Updates.
https://help.salesforce.com/s/articleView?id=release-notes.rn_ru_ga.htm&release=228&type=5
Other Security Changes: Changes to Security Release Notes, Security Center General Availability, a Connectivity Change, and New Crypto Class Support
Identity for Customers and Partners and Data Protection and Privacy topics moved to a new home in the release notes: Customer 360 Truth. Monitor multiple orgs with Security Center (generally available). Review and update your TLS ciphers, and take advantage of more Crypto class values.
Salesforce Shield: More Real-Time Monitoring Events, Legacy Transaction Security End of Life, and More Field Encryption
Real-Time Event Monitoring helps you identify and respond to anomalous API usage, monitor bulk API queries, and audit when users download data in Einstein Analytics. The Event Monitoring Analytics App helps you analyze exceptions without manually uploading datasets, and legacy Transaction Security framework is disabled. Shield Platform Encryption continues to offer another layer of security for more personally identifiable data. Encrypt Health Cloud data and fields on the Identity object.
https://help.salesforce.com/s/articleView?id=release-notes.rn_security_shield.htm&release=228&type=5