Domains: Required My Domain, and Shorter URLs
New Salesforce orgs get a My Domain by default and existing orgs must define one by Winter ’22. For customers with a My Domain, we’re removing instance names from My Domain URLs through a release update.
Authentication and Identity: Multi-Factor Authentication Assistant, Mobile Device Tracking, and SAML Updates
Changes in Salesforce Identity start with a Multi-Factor Authentication Assistant that helps you safeguard your Salesforce data. We also retired two-factor authentication terminology and moved to the industry standard term of multi-factor authentication. You can enhance your Salesforce org’s security with Mobile Device Tracking. Web applications can now enable Cross-Origin Resource Sharing (CORS) to access resources from certain Salesforce OAuth endpoints. Secure outbound SAML messages when Salesforce is the identity provider.
Security, Privacy, and Identity: Security Center and Mobile Device Tracking Generally Available, Required My Domain, and More Real-Time Monitoring Events and Field Encryption
Maintain security, privacy, and governance policies for multiple orgs with Security Center, now generally available. View and manage mobile device access to your org with Mobile Device Tracking, generally available. New Salesforce orgs get a My Domain by default and existing orgs must define one. Keep a closer eye on your org with three new Real-Time Monitoring Events. Encrypt fields associated with health intake documents, and encrypt some Financial Services Cloud documents.
https://help.salesforce.com/s/articleView?id=release-notes.rn_security.htm&release=228&type=5
Require Permission to View Record Names in Lookup Fields (Previously Released Update)
To better protect your Salesforce org’s data, we restricted who can view record names in lookup fields. Users must have Read access to these records or the View All Lookup Record Names permission to view this data. This update also applies to system fields, such as Created By and Last Modified By. This update was first made available in Spring ’20.
Where: This change applies to Lightning Experience and Salesforce Classic in all editions.
When: Salesforce enforces this update in Spring ’21. To get the major release upgrade date for your instance, go to Trust Status, search for your instance, and click the maintenance tab.
Why: Admins have more control over what users see in records. Currently, users can view record names in lookup fields without Read access to those records.
Changes to Record Type Creation UI in Setup
To clarify what users can and can’t do when they have access to a record type, we updated the description text and one of the profile column labels for Step 1 of the New Record Type creation process.
Where: This change applies to Lightning Experience and Salesforce Classic in Professional, Enterprise, Performance, Unlimited, and Developer editions.
Why: The Enable for Profile column header is now Make Available, and the description more clearly outlines what users with access to this record type can do.
Choose Your Utility Bar Alignment
Customize where your Salesforce org’s utility bar appears on the screen. You can choose to align the utility bar to the bottom right or the bottom left of the screen. The default alignment matches the directionality of the user’s language.
Where: This change applies to Lightning Experience in Group, Essentials, Professional, Enterprise, Performance, Unlimited, and Developer editions.
Who: Admins with the View Setup and Configuration and Customize Application can modify the utility bar alignment.
How: To change the utility bar alignment:
General Setup: Utility Bar Alignment Customization, Dynamic Submit for Approval Action, and Record Type UI Changes
Customize where your org’s utility bar appears on the screen. Display the Submit for Approval action only when a record is eligible for approval. Clearer description text and an updated profile column label for Step 1 of the New Record Type creation process.
Custom Metadata Types: Support for Geolocation Entities and Metadata Relationship Field Type User Interface Display
You can now create entity particle relationships for geolocation field types. Also, the dropdown menu for the metadata relationship field type shows which entities are supported.
- Custom Metadata Types Support Geolocation Field Types Relationships
Support for entity particle relationships was introduced in Summer ’20, with the exception of geolocation field types. With Winter ’21, you can now create geolocation field type relationships. - View Supported Relationship Entities When Creating Custom Metadata Types
When you a create metadata type, the metadata relationship field type menu now shows you which entities are supported. In previous releases, entities for relationships were only shown if they had a Salesforce Classic, Custom Fields setup page. This restriction was removed.
Secure Guest Users’ Org-Wide Defaults and Sharing Model Can’t Be Disabled
The Secure guest user record access setting was enabled in all Salesforce orgs with communities or sites in Summer ’20, but could still be disabled during that release. In Winter ’21, this setting is enabled in all orgs and can no longer be disabled. The Secure guest user record access setting enforces private org-wide defaults for guest users and restricts the sharing mechanisms that you can use to grant record access to guest users.
Where: This change applies to orgs with active communities and sites in Essentials, Enterprise, Performance, Unlimited, and Developer editions.
When: The timelines for the rollout and enforcement of this setting are published in Guest User Security Policies and Timelines.
Deploy Organization-Wide Defaults and Criteria-Based Sharing Rules Together
You can now simultaneously update the sharingModel field for an object and create new criteria-based or guest user sharing rules via the Metadata API. Previously, you deployed these changes in separate packages. You still deploy owner-based sharing rules separately from organization-wide default changes.
Where: This change applies to Lightning Experience and Salesforce Classic in Professional, Enterprise, Performance, Unlimited, and Developer editions.