Changes to Session-Security-Level Policies
To better secure sensitive operations in the Users Setup page, you can require users to have a high-assurance session level before accessing the page. Also, we removed the View Event Log Files setting from the Session Security Level Policies section.
Where: This change applies to Salesforce Classic and Lightning Experience in all editions.
How: From Setup, in the Quick Find box, enter Identity Verification, and then select Identity Verification. In the Session Security Level Policies section, for Manage Users, select Raise session to high assurance. Click Save.
Allow Redirects to External URLs Without a Warning Message
Whitelist URLs outside the Salesforce domain that your users can navigate to directly when the Warn users before they are redirected outside of Salesforce setting is enabled. For URLs that you don't whitelist, users see a warning message before they get redirected.
Where: This change applies to Salesforce Classic in all editions.
How: From Setup, in the Quick Find box, enter Whitelisted URLs for Redirects, and then select Whitelisted URLs for Redirects. Click New URL
Automatically Assign Records Created by Guest Users in Salesforce Sites to a Default Owner
To increase the security of your Salesforce data, set up your org so that guest users are no longer automatically the owner of records they create in Salesforce Sites. When a guest user creates a record in a Salesforce Site, the record is assigned to a default active user, who becomes the owner.
Where: This change applies to orgs with active Salesforce Sites in Essentials, Unlimited, Performance, and Developer editions.
Why: To follow Salesforce security best practices, designate an internal org user to be the owner of records created by guest users. While we strongly encourage you to assign a default owner, changing record ownership can affect your guest users’ ability to access records. Test all changes in a sandbox environment to see the effects on data sharing and visibility before you change your implementation in production.
How: From Setup, in the Quick Find box, enter Sites, and then select Sites. Select Reassign new records created by guest users to the default owner. Click Save.
If no default owner is chosen in the org, Salesforce automatically assigns the Salesforce Site owner as the owner of records created by guest users.
Data Protection and Privacy: Party Consent, Communication Subscription, and Contact Point Objects
Store data related to your customers' general consent preferences and the communications that they subscribe to. You can also associate multiple email addresses or phone numbers to individuals or person accounts, and manage their preferred time and consent to be contacted.
- Keep Track of Customer Consent Preferences
Use the Party Consent object to store information related to your customers’ general consent preferences, such as whether they agree to have their data collected or shared. Indicate when and how you captured consent as well. You can associate multiple party consent records to an individual or person account record. - Manage Your Customers’ Communication Subscriptions
Keep track of data related to the communications your customers subscribe to, such as newsletters or appointment reminders. Store when and how your customers consented to be contacted and information on their preferred timing. You can also record the channels, such as email addresses and phone numbers, through which you can reach them. - Store Multiple Contact Points and Customer Consent Information
To help you better reach your customers, you can now specify multiple email addresses or phone numbers for an individual or person account. Previously, our data model only allowed for one phone number or email to be associated to a single customer. Now, using contact point email and contact point phone, you can also add details such as the best time to reach out to a contact or how they prefer to be contacted. Plus, you can reference these records from a contact point consent record to store your customer’s consent to being contacted this way.
Salesforce Shield: Real-Time Event Monitoring Threat Detection (Beta), Event Monitoring Analytics App Improvements, and Platform Encryption for Platform Events
Use Real-Time Event Monitoring platform events to detect common threats to your org (Beta). We improved the performance of the Event Monitoring Analytics app. The legacy transaction security policy framework will be retired in Summer ’20. Shield Platform Encryption now supports Platform Events in addition to Change Data Capture Events.
- Shield Platform Encryption: Encryption for Platform Events
Shield Platform Encryption now supports Platform Events, adding an extra layer of protection for events that involve sensitive information. Remove the Manage Encryption Keys permission from system admin profile with a critical update. - Event Monitoring: New Threat Detection Real-Time Events (Beta), Legacy Transaction Security Retiring, Event Monitoring Analytics App Improvements
Detect threats to your org, such as report execution anomalies and credential stuffing, with three new Real-Time Event Monitoring events. We are retiring the legacy transaction security framework in the Summer ’20 release, so migrate your existing policies to the enhanced framework. Also, we improved the performance of the Event Monitoring Analytics app.
https://help.salesforce.com/s/articleView?id=release-notes.rn_security_shield.htm&release=224&type=5
Domains: Custom Domains for Sandboxes (Pilot), Salesforce Edge, Instanceless URLs, and Certificate Changes for My Domains
Test your Salesforce Sites and Communities in a sandbox using custom domains (Pilot). Customers with a My Domain can accelerate domain requests with Salesforce Edge. Remove instance names from My Domain URLs through critical updates or sandbox refreshes.
- Use Custom Domains for Sandboxes (Pilot)
Develop and test your Salesforce Sites and communities within your sandboxes using custom domains. This feature allows you to test new custom domains in a sandbox before deploying them to Salesforce production. - Route My Domains Through Salesforce Edge (Previously Released Critical Update)
We’re accelerating domain requests for My Domains. With this update, you keep the same My Domain address, but requests go through Salesforce Edge. Salesforce Edge uses machine-learning technology to improve connectivity and performance. You can acknowledge this update to let Salesforce move your org’s My Domain to the new service before the July 2020 auto-activation date. This critical update was first made available in Winter ’20. - Stabilize the Hostname for My Domain URLs in Sandboxes (Previously Released Critical Update)
We’re removing instance names from MyDomain URLs for sandboxes. The instance name identifies where your Salesforce sandbox org is hosted. Removing the instance name makes the URL cleaner and easier for users to remember. For example, MyDomain--SandboxName.my.salesforce.com replaces MyDomain--SandboxName.cs5.my.salesforce.com. This critical update was first made available in Summer ’18. - Stabilize URLs for Visualforce, Experience Builder, Site.com Studio, and Content Files (Previously Released Critical Update)
We’re removing the instance names from Visualforce, Experience Builder, Site.com Studio, and content file URLs. An instance name identifies where your Salesforce org is hosted. Instanceless domains are cleaner and easier for users to remember. This critical update applies to orgs that have a deployed My Domain. After this update, a URL that includes the instance name, such as a bookmark, automatically redirects to the new hostname. This critical update was first made available in Spring ’18. - Get Stabilized My Domain URLs in New and Refreshed Sandboxes
As part of our effort to stabilize domains by removing instance names from their URLs, the My Domain URL format is changing for sandboxes. When you create or refresh a sandbox with a deployed My Domain, the sandbox name within the hostname becomes lowercase. Also, the “Stabilize the Hostname for My Domain URLs in Sandboxes” and “Remove Instance Names From URLs for Visualforce, Experience Builder, Site.com Studio, and Content Files” critical updates are automatically activated. These critical updates remove the instance name from the sandbox URLs.
Allow Users to Connect Orgs as a Data Source to Cross-Cloud Applications
As a Salesforce admin, you can grant designated admins permission to connect Salesforce orgs as data sources to cross-cloud Salesforce applications, such as Customer 360 Data Manager. Connecting an org as a data source lets you connect customer data across your enterprise to create a single view of your customer. For example, service agents can view a customer’s order history in Service Console without swiveling their chairs to Commerce Cloud.
Where: This change applies to Lightning Experience and Salesforce Classic in all editions.
When: This user permission was added in the Winter ’20 release.
Who: The Connect Org to Customer 360 Data Manager permission is automatically enabled for Salesforce admins.
How: In your org, create a permission set that grants the Connect Org to Customer 360 Data Manager permission. Assign the permission set to the designated admin who is creating the connection. The admin is required to log in to the org to create the connection.
Discover the Session Status for Content, Visualforce, and Lightning Pages
If a Salesforce content, Visualforce, or Lightning page doesn’t load, you can use a new child_session parameter in the Salesforce OpenID Connect token introspection endpoint to discover its session status. For example, a page with a status of inactive (an expired session) or missing (a non-existent session) no longer has an authorized session, so the user must log back in to the Salesforce org.
Where: This change applies to Lightning Experience and Salesforce Classic in all editions.
Why: OAuth supports the extension of access tokens as a bridge to other authorization frameworks. In Salesforce, this extension is implemented when users access Salesforce content, Visualforce, and Lightning pages after successfully logging in to a Salesforce org. These pages launch as child sessions, using the org’s authenticated session as a bridge. However, if the child sessions don’t have a current access token from the org’s session, they fail to launch.
How: Include the new child_sessions parameter in POST requests to the Salesforce OpenID Connect token introspection endpoint. You can only include this parameter for introspection of active org sessions. It doesn’t work with introspection of refresh tokens.
The OAuth Approval Page Timeout Has Increased
You now have two hours to approve access to connected apps on the OAuth Approval page. Previously, the page timed out after 15 minutes.
Where: This change applies to Lightning Experience and Salesforce Classic in all editions.
Apply the Request Signature Method to Your Single Logout Settings
For single sign-on, the Request Signature Method (RSM) applies a hashing algorithm—either RSA-SHA1 or RSA-SHA256—for encrypted requests. You can now apply the selected single sign-on RSM to your single logout (SLO) settings.
Where: This change applies to Lightning Experience and Salesforce Classic in all editions for Federated Authentication, and in Professional, Enterprise, Performance, Unlimited, Developer, and Database.com editions for Delegated Authentication.
How: Select Use Selected Request Signature Method for Single Logout to apply the selected Request Signature Method during SLO. If you don’t select this option, the default RSM (RSA-SHA1) is applied.
https://help.salesforce.com/s/articleView?id=release-notes.rn_auth_rsm_slo.htm&release=224&type=5