Control Who Gets Read Access to Custom Settings
You can now control the access of custom settings at a granular level by granting direct Read access to specific custom settings through profiles and permission sets.
Where: This change applies to Lightning Experience and Salesforce Classic in Professional, Enterprise, Performance, and Unlimited editions.
When: This feature is a late-breaking addition to the Winter ’20 release.
Who: Users with the Customize Application permission can grant read access to specific custom settings through profiles and permission sets.
How: To grant a Profile or Permission Set read access to specific custom settings, enable the Restrict access to custom settings org permission. Then enable access to specific custom settings.
Require Customize Application Permission for Direct Read Access to Custom Settings (Critical Update, Enforced)
Access for users without the Customize Application permission to read unprotected custom settings is revoked as part of this critical update. Using different APIs that are provided by Salesforce, users without the Customize Application permission could read unprotected custom settings. Following the “secure by default” approach, this access is revoked.
Where: This change applies to Lightning Experience and Salesforce Classic in Contact Manager, Essentials, Professional, Enterprise, Performance, Unlimited, and Developer editions.
When: This critical update is scheduled to be enforced on sandbox instances on January 2, 2020 in the Spring ’20 release. It will not be rolled out to all instances on January 2, 2020. Sandbox instances are upgraded 4–6 weeks before a release goes into production. To find the exact activation date for your instance, refer to https://status.salesforce.com.
How: When this critical update is enforced on the instance, users without the Customize Application permission can no longer access custom settings. To minimize the impact on your users, admins with the Customize Application permission can grant read access to specific custom settings, or to all custom settings.
Changes to Sharing API Access
Access to sharing rules and sharing sets through the Salesforce API is available for users with the View Setup and Configuration permission. Editing sharing rules and sharing sets through the API is available for users with the Manage Sharing permission.
Where: This change applies to Lightning Experience and Salesforce Classic in Professional, Enterprise, Performance, Unlimited, and Developer editions.
Safeguard Your Data by Setting External Access Levels for the Lead and Campaign Objects (Generally Available)
You can now set external access levels for the Lead object, which was previously in beta, and the Campaign object. Select more restrictive access for external users without changing the default internal access level. The objects available for external org-wide defaults vary depending on your Salesforce org’s licenses and other settings.
Where: This change applies to Lightning Experience and Salesforce Classic in Professional, Enterprise, Performance, Unlimited, and Developer editions.
How: To set external org-wide defaults, from Setup, enter Sharing Settings in the Quick Find box, then select Sharing Settings. Under Organization-Wide Defaults, edit the default external access.
The External Sharing Model Can No Longer Be Disabled
To better protect your Salesforce org’s data, you can no longer disable the external sharing model after it's enabled in your org.
Where: This change applies to Lightning Experience and Salesforce Classic in Professional, Enterprise, Performance, Unlimited, and Developer editions.
How: The external sharing model allows you to customize the access levels for internal and external users. We recommend setting org-wide defaults to Private for external users.
From Setup, enter Sharing Settings in the Quick Find box, then select Sharing Settings. Under Organization-Wide Defaults, edit the Default Internal and External Access as required by your business needs.
External Org-Wide Defaults Are Enabled by Default in All New Orgs
To better secure your data, the External Sharing Model is enabled by default in all Salesforce orgs created in Spring ’20 or later. External org-wide defaults let you set more restrictive levels of access for external users, instead of giving internal and external users the same default access. In these newly created orgs, external access levels are initially set to Private for all objects.
Where: This change applies to Lightning Experience and Salesforce Classic in Professional, Enterprise, Performance, Unlimited, and Developer editions.
How: We recommend that you maintain a strict access level for external users, but you can edit your external org-wide defaults. From Setup, enter Sharing Settings in the Quick Find box, then select Sharing Settings. Under Organization-Wide Defaults, edit the default external access.
Manage Permissions in Permission Set Groups with a Muting Permission Set (Generally Available)
A muting permission set is a handy way to increase security and ensure that only components that are required by your organization and users are accessible and, conversely, those components that shouldn’t be accessed are not available. When used along with permissions, a muting permission set gives you granular control over permissions and helps make sure you're complying with the principle of least privilege.
Where: This change applies to Salesforce Classic (not available in all orgs), Lightning Experience. Enterprise, Performance, Unlimited, and Developer editions.
Why: Suppose that your Sales Staff Users permission group contains three permission sets. And one of those three permission sets contains a Delete permission that you no longer want all group members to have. To complicate things, you also have a Managers permission set group that references the Sales Staff Users permission set. What can you do to implement this permission restriction? Instead of creating another permission set, you can use a muting permission set to constrain the Delete permission. The muting permission set contains the Delete permission that you want to disable. When you add the muting permission set to the Sales Staff Users group, those members no longer have the delete permission, but the Managers members do.
Track Permission Set Edits with a New Confirmation Menu
It just got easier to track bulk edits on permissions. We’ve improved readability and security so that multiple-selection permissions and any permission dependencies are summarized on a separate page. With the Permission Changes Confirmation page, you can easily identify and review all added and removed permissions before they become part of your permission ecosystem. Previewing the permission edits summary helps you better manage and maintain security control for your users and organization.
Where: This change applies to Salesforce Classic (not available in all orgs), Lightning Experience. Enterprise, Performance, Unlimited, and Developer editions.
How: From Setup, choose Permission Sets, modify permissions, and click save to review your choices on Permission Changes Confirmation page.
Group Permission Sets Based on User Job Function for Easier Assignment (Generally Available)
Now you can assign users a single permission set group instead of multiple permission sets. Permission set groups combine selected permission sets to provide all the permissions that users need for their job. Similarly, remove individual permissions from a group with the permission muting feature to ensure that users do not get permissions that are not relevant to their job functions. A new user interface helps you create and manage permission set groups.
Where: This change applies to Salesforce Classic (not available in all orgs), Lightning Experience. Enterprise, Performance, Unlimited, and Developer editions.
Why: Suppose that you have employees in your sales department who work with Sales Cloud Analytics templates and apps. They also create, edit, and delete surveys and read, create, edit, and delete accounts. You have three permission sets that contain the permissions needed: Sales Cloud Einstein, Survey Creator, and a permission set based on the Standard User Profile. You assign each permission set separately to your users.
You can combine the permission sets into one meaningful permission set group and then assign the permission set group to the sales employees. In this example, the permission set group Sales Staff Users contains the combined permissions of all the permission sets that you added to the group. Salesforce also aggregates and resolves permissions across all permission sets in the permission set group to ensure that inheritance and dependencies are maintained.
How: From Setup, choose Permission Set Groups to view your permission set groups and create groups.
https://help.salesforce.com/s/articleView?id=release-notes.rn_forcecom_psg.htm&release=224&type=5
Permission Set Groups: Greater Flexibility in Granting Permissions (Generally Available)
Permission set groups are an ideal way to consistently and reliably assign permissions to a group of users. Assign users a single permission set group instead of multiple permission sets. Permission set groups combine selected permission sets to provide all the permissions that users need for their job function. Remove individual permissions from a group with the muting permission set feature to ensure that permissions do not exceed user job functions. This change applies to Lightning Experience and Salesforce Classic.