Share Data with Partners via External Account Hierarchies

External account hierarchies take the complexity out of sharing data. Now partners and customers can easily share data with other external accounts in their hierarchy.

Where: This change applies to Lightning communities accessed through Lightning Experience and Salesforce Classic in Performance, Unlimited, and Developer editions.

Who: This feature is available to Partner and Customer users only.

What: Like Salesforce role hierarchies, data that belongs to accounts in an external account hierarchy is available to the parent in the hierarchy. As a result, external users don’t have to rely on sharing rules to access data from their child accounts.

How: Enable external account hierarchies in Communities Settings. After you enable the preference, the External Account Hierarchy object is available in your org.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_external_account_hierarchy.htm&release=226&type=5


Assign Your Community’s Login Page Type to Embedded Login

Configure Embedded Login to use the discoverable login page type or any other custom login page type already set up for your community.

Where: This change applies to Lightning communities accessed through Lightning Experience and Salesforce Classic in Enterprise, Performance, Unlimited, and Developer editions.


Set Up Two-Factor Authentication for External Identity with a User Permission

Where: This change applies to Lightning communities accessed through Lightning Experience and Salesforce Classic in Essentials, Performance, Unlimited, and Developer editions.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_2FA_external_identity_license.htm&release=226&type=5


Ensure Guest User Access to Emails Created with Visualforce Email Templates

Protect access to your company’s data when you send emails that use Visualforce Classic email templates to guest users. Review and update these templates so that they can still be used.

Where: This change applies to Salesforce orgs with active public communities, sites, and portals in Enterprise, Performance, Unlimited, and Developer editions.

When: This security policy was released in Spring ’20 and was immediately enforced.

Who: This change applies to Visualforce email templates that target guest users in communities.

Why: Emails that use Visualforce email templates send information based on a user’s access to Salesforce data. But because data access for guest users is limited in Salesforce, the template doesn’t work.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_guest_visualforce_templates-226.htm&release=226&type=5


Opt Out of Turning Off Community-Specific Setting for Guest Users to See Other Members (Previously Released Update)

By activating this update, you opt out of turning off the community-specific Let guest users see other members of this community setting in the Winter ’21 release.

Where: The update is visible in Salesforce orgs with active public communities in Enterprise, Essentials, Unlimited, Performance, and Developer editions.

When: The Let guest users see other members of this community setting is automatically disabled in all communities in Winter ’21. This update gives you the extra time you may need to get ready.

How: Before Winter ’20, the Community User Visibility setting, when enabled, allowed guest users and authenticated community users to see each other within the community. In the Winter ’20 release, we introduced a new community-specific setting, Let guest users see other members of this community, that lets admins control guest user visibility independently from community user visibility.

Depending on your security configuration, this setting might allow a guest user, essentially anyone on the internet, to access community users’ personally identifying information. This can include first and last name, email, custom, and other fields.

To protect your customer data and privacy, Salesforce is turning off the Let guest users see other members of this community setting for all communities.

Depending on your business needs, enabling this setting and allowing guest users to see one another may be required for your site to function properly. Therefore, we are asking that you reassess and validate the need to enable Let guest users see other members of this community for each community. If you have one or more communities that must have this setting turned on, activate this update to opt out of the Winter ’21 update. However, we encourage you to work towards modifying your site's customization to allow this setting to be disabled. Limiting guest user visibility is a Salesforce security best practice.

If you don’t activate this update, the Let guest users see other members of this community setting is turned off on all your communities (not just the ones created after Winter ’20). Make sure to assess all the communities in your org, including the ones created after Winter ’20.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_GUV_opt_out.htm&release=226&type=5


Reduce Object Permissions for Guest Users by the Winter ’21 Release (Security Alert)

With the Winter '21 release, Salesforce is removing the View All Data, Modify All Data, and delete permissions for guest users, and they can never be used for guest users on any objects. If a custom or standard object has View All Data, Modify All Data, or delete permissions for guest users, all the permissions are turned off with the Winter ’21 release. Reduce object permissions for guest users if they have View All Data, Modify All Data, or delete permissions on a standard or custom object.

Where: This change applies to all Salesforce orgs with one or more standard or custom objects with View All Data, Modify All Data, update, or delete permissions enabled for guest users.

How: Follow the step-by-step recommendations of the security alert if it appears in your org.

If a security alert appears in your org, your org data may be exposed to guest users because you have one or more standard or custom objects with View All Data, Modify All Data, update, or delete permissions enabled for guest users.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_reduce_object_perms.htm&release=226&type=5


Modify All Data, View All Data, Edit, and Delete Permissions on Guest User Profiles in Orgs Created Before Summer ’20

In orgs created before the Summer ’20 release, we're removing the View All Data, Modify All Data, and delete permissions on custom and standard objects for guest users, but only if they were never enabled on the guest profile or permission sets for guest users. In orgs created before the Summer ’20 release, guest user profiles retain guest edit permissions on all custom objects and the following standard objects: Order, Contract, and Survey Response. Guest users only had edit permissions on the three standard objects mentioned, and this behavior has not changed. If your org was created before the Summer ’20 release, and you have View All Data, Modify All Data, edit, or delete permissions on any object for a guest user, you’re notified by a Security Alert to make the necessary changes to your org.

Where: This change applies to all orgs with guest user profiles for communities, Site.com sites, and Salesforce Sites.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_guest_only_read_create.htm&release=226&type=5


Modify All Data, View All Data, Edit, and Delete Permissions on Guest User Profiles in Orgs Created in Summer ’20

Orgs created in the Summer ’20 release don’t have Modify All Data, View All Data, or delete permissions on any standard or custom objects for guest user profiles. Guest users in orgs created in Summer ’20 still have edit permissions for custom objects and the following three standards objects: Order, Contract, and Survey Response.

Where: This change applies to all orgs with guest user profiles for communities, Site.com sites, and Salesforce Sites.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_guest_new_orgs_CRUD.htm&release=226&type=5


View All Users and Other Permissions Disabled in Guest User Profiles (Previously Released Security Alert, Enforced)

Guest users typically don’t need access to view all users in a Salesforce org, so to promote data security, we disabled the View All Users permission in guest user profiles. If you have a production org that was created before Winter ’20, we recommend that you check guest user access and deselect the View All Users permission in all your guest user profiles. To enhance security, we also removed these permissions from the guest user profile: Can Approve Feed Post and Comments, Enable UI Tier Architecture, Remove People from Direct Messages, View Topics, and Send Non-Commercial Email.

Where: This change applies to orgs with active communities in Enterprise, Essentials, Unlimited, Performance, and Developer editions.

When: The timelines for the rollout and enforcement of this setting are published in Guest User Security Policies and Timelines.

How: These changes are auto-enabled in your org. However, you can opt out. In the Summer ’20 release, these changes are mandatory and you no longer have the option to opt out.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_guest_perms_removed.htm&release=226&type=5


Secure Guest Users’ Org-Wide Defaults and Sharing Model (Previously Released Security Alert, Enforced)

Learn about the Secure guest user record access setting in this security alert, and how to safeguard your org’s data. This setting enforces private org-wide defaults for guest users and restricts the sharing mechanisms that you can use to grant record access to guest users. If you have a Salesforce org created before Winter ’20, we recommend that you review the external org-wide defaults, public groups, queues, manual sharing, and Apex managed sharing that you use to grant access to guest users. Then replace the access previously granted by these sharing mechanisms with guest user sharing rules before the security alert is enforced.

Where: This change applies to orgs with active communities and sites in Enterprise, Essentials, Unlimited, Performance, and Developer editions.

When: The timelines for the rollout and enforcement of this setting are published in Guest User Security Policies and Timelines.

How: Review the required actions before this security alert is enforced. From Setup, enter Security Alerts in the Quick Find box, then select Security Alerts. For Secure Guest Users’ Org-Wide Defaults and Sharing Model, click Get Started. Follow the instructions in the step-by-step guides for reviewing guest user sharing settings and creating guest user sharing rules.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_guest_sharing_security_alert.htm&release=226&type=5


Privacy Preference Center