Guest Users Can’t Be Assigned as Owners of Already Existing Records

Before the Summer ’20 release, guest users couldn’t be assigned as owners of newly created records. Starting in Summer ’20, guest users can’t be assigned as owners of records already existing in the org.

Where: This change applies to all orgs with guest user profiles for communities, Site.com sites, and Salesforce Sites.

How: This change is enforced in new orgs created after the Summer ’20 release. Check out Opt Out of Guest User Security Policies Before Summer ’20 (Critical Update) for orgs created before the Summer ’20 release.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_guest_as_owner.htm&release=226&type=5


Opt Out of Guest User Security Policies Before Summer ’20 (Previously Released Update)

By activating this update, you opt out of three policies aimed at increasing your data security for guest, or unauthenticated, users. Activating this update opts your org out of having the following settings automatically enabled with the Summer ’20 release: Secure guest user record access, Assign new records created by guest users to the default owner, and Assign new records created by Salesforce Sites guest users. If your org already has these settings enabled, activating this update doesn’t change your configuration.

Where: The release update is visible in orgs with active communities in Enterprise, Essentials, Unlimited, Performance, and Developer editions.

When: The Secure guest user record access, Assign new records created by guest users to the default owner, and Assign new records created by Salesforce Sites guest users settings are automatically enabled with the Summer ’20 release. This update gives you the extra time to get ready. If you opt out of these settings for the Summer ’20 release, you must comply with our new guest security policies before Winter ’21, when they are enforced on all orgs.

How: To opt out of automatically enabling these settings, activate the update. To access the settings in the UI to see if they are enabled or not:

  • From Setup, enter Sharing Settings in the Quick Find box. Select Sharing Settings. You can see the Secure guest user record access checkbox on the page.
  • From Setup, enter Communities Settings in the Quick Find box, then select Communities Settings. You can see the Assign new records created by guest users to the default owner checkbox on the page.
  • From Setup, enter Sites in the Quick Find box, then select Sites. You can see the Assign new records created by Salesforce Sites guest users checkbox on the page.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_guest_opt_out.htm&release=226&type=5


Automatically Assign Records Created by Guest Users to a Default Owner (Previously Released Security Alert)

To increase the security of your Salesforce data, set up your org so that guest users are no longer automatically the owner of records they create. Instead, when a guest user creates a record, the record is assigned to a default active user in the org, who becomes the owner.

Where: This change applies to orgs with active communities in Enterprise, Essentials, Unlimited, Performance, and Developer editions.

Why: Having an internal org user be the owner of records created by guest users is a Salesforce security best practice. While we strongly encourage you to assign a default owner, changing record ownership can affect your guest users’ ability to access records. Test all changes in a sandbox environment to see the effects on data sharing and visibility before you change your implementation in production.

How: From Setup, enter Communities Settings in the Quick Find box, then select Communities Settings. Select Assign new records created by guest users to the default owner. Click Save.

In newly created communities, Salesforce automatically assigns the user that created the community as the default owner of all records created by guest users. Change the default owner in the Administration workspace of your community, under Preferences.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_reassign_guest_records.htm&release=226&type=5


Block Certain Fields in the User Record for Orgs with Communities and Portals (Previously Released Security Alert and Update, Enforced)

Salesforce is giving customers the option to enable a user setting that allows the hiding of certain personal information fields on the user records in orgs with communities or portals. The fields are hidden from view when external users are accessing user records. External users can still see their own user records. This change doesn’t apply to queries running in System Mode.

Where: This change applies to all orgs with communities or portals.

When: This update was activated automatically on January 5, 2020 in production orgs.

How: Salesforce is introducing an org setting that allows for the hiding of other users' personal information in pages showing the user record to external user profiles, and in SOSL and SOQL queries that run as external users.

The affected fields are

  • Alias
  • EmployeeNumber
  • FederationIdentifier
  • SenderEmail
  • Signature
  • Username
  • Division
  • Title
  • Department
  • Extension

Admins can enable the setting Hide Personal Information for the org under User Management Settings. After enabling the setting, searches on user records don't show the affected fields of other users to external users.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_user_profile_cruc.htm&release=226&type=5


Guest User: Security Policies Enforced

In the past few releases, Salesforce implemented various security settings that comprise an overall public site security policy. In Summer ’20, some settings are auto-enabling in your org, which you can opt out of, though we don’t recommend it. Starting with the next release, Winter ’21, the public site security settings are enabled, and you no longer have the option of opting out. Make sure your org enables all the security settings needed, and test out your implementation.

https://help.salesforce.com/s/articleView?id=release-notes.rn_networks_guest_user.htm&release=226&type=5


Permission Changes for Service Cloud Features

Review access changes to Service Cloud features that take effect with the Summer ’20 release.

Entitlements and Milestones

  • Access to entitlement templates, entitlement processes, work order milestones, and milestone types is limited to Salesforce admins, users with access to the Case, Entitlement, or Work Order objects, and users with the View Setup and Configuration permission.

Linked Articles

  • Access to linked articles in the API is limited to users with access to the parent record linked to the knowledge article.

https://help.salesforce.com/s/articleView?id=release-notes.rn_service_permissions.htm&release=226&type=5


Permission Changes for Sales Cloud Features

Review access changes to Sales Cloud features that take effect with the Summer ’20 release.

Duplicate Management
-Access to duplicate rules, duplicate jobs, matching rules, and matching criteria through the API is limited to authenticated users with the View Setup and Configuration permission.

Email
-Access to email domain filters in the API is limited to authenticated users with the Email Administration, Customize Application, and View Setup and Configuration permissions. Access to organization-wide email addresses for user profiles is limited to authenticated users.

Enterprise Territory Management
-Access to territories and their assignments, associations, categories, and models is limited to standard and partner users.

https://help.salesforce.com/s/articleView?id=release-notes.rn_sales_other_changes_permissions.htm&release=226&type=5


Require Secure HTTPS Connections (Update, Enforced)

Require Secure HTTPS Connections was an update in Spring ’20 and was enforced in production orgs on May 1, 2020. As part of updates related to Google Chrome’s SameSite cookie changes, HTTPS connections are required to access Salesforce. HTTP connections are no longer permitted. This update enabled the Require secure connections (HTTPS) setting on the Session Settings Setup page and prevented it from being disabled. The Require secure connections (HTTPS) for all third-party domains setting isn’t affected by this update.

Where: This change applies to Lightning Experience, Salesforce Classic, and all versions of the Salesforce app in all editions.

When: This update was activated automatically on May 1, 2020 in production orgs.

To view this update, from Setup, in the Quick Find box, enter Critical Updates, then select Critical Updates. For Require Secure HTTPS Connections, click Review.

https://help.salesforce.com/s/articleView?id=release-notes.rn_general_https_cruc_enforced.htm&release=226&type=5


Changes to Named Credentials

Access to named credentials through the Salesforce API is available for users with the View Setup and Configuration permission.

Where: This change applies to Lightning Experience and Salesforce Classic in all editions.

https://help.salesforce.com/s/articleView?id=release-notes.rn_security_other_changes.htm&release=224&type=5


Monitor More Changes in the Setup Audit Trail

To help you track the recent setup changes that you and other admins make to your Salesforce org, we added new events to the Setup Audit Trail.

Where: This change applies to the Setup Audit Trail, available in Lightning Experience and Salesforce Classic in Contact Manager, Essentials, Group, Professional, Enterprise, Performance, Unlimited, Developer, and Database.com editions.

Why: Track changes to:

  • Email Deliverability—Your access to send email in Salesforce, set through the Access level field on the Deliverability Setup page.
  • Connected Apps—Your connected app’s PIN length and inactivity timeout, set in the Mobile Integration section of your connected app’s settings. Access these settings from the Manage Connected Apps Setup page.
  • Notifications—Your notification delivery settings for custom notification types, set from the Custom Notifications Setup page, and for standard notification types, set from the Notification Delivery Settings Setup page. You can track changes to mobile, desktop, and connected app delivery settings.

How: To view the audit history, from Setup, in the Quick Find box, enter View Setup Audit Trail, and then select View Setup Audit Trail.

https://help.salesforce.com/s/articleView?id=release-notes.rn_security_other_changes.htm&release=224&type=5


Privacy Preference Center