Add Read-Only Objects to Your Backup Policy
Version 2.19 of the Salesforce Backup managed package now supports some read-only objects, including History associated objects and more Activities objects. Add these objects to your policy when you want to retain records for future auditing purposes such as reviewing changes to important fields over time.
Where: This change applies to Lightning Experience in Enterprise, Professional, and Unlimited editions.
Who: This change applies to editions that have the Salesforce Backup add-on subscription.
How: In the Salesforce Backup app, on the Backup tab, supported read-only objects appear in the list of available objects. Select an object, and enable it in your policy.
Set a Custom Backup Schedule
Every organization has their own rhythm, schedules, and work cadences. You can now customize your backup schedule to suit your needs. Configure your policy to capture backups monthly, weekly, daily, or hourly. You can also choose a start time and preferred time zone. This change is available in v2.19 of the Salesforce Backup managed package.
Where: This change applies to Lightning Experience in Enterprise, Professional, and Unlimited editions.
Who: This change applies to editions that have the Salesforce Backup add-on subscription.
How: In the Salesforce Backup app, on the Backup tab, click Configure Policy Defaults. Then choose when you want the app to make backups.
Salesforce Backup
Salesforce Backup managed package expands the list of supported objects to cover read-only objects. Choose when your backups run with new customizable backup scheduling.
- Set a Custom Backup Schedule
Every organization has their own rhythm, schedules, and work cadences. You can now customize your backup schedule to suit your needs. Configure your policy to capture backups monthly, weekly, daily, or hourly. You can also choose a start time and preferred time zone. This change is available in v2.19 of the Salesforce Backup managed package. - Add Read-Only Objects to Your Backup Policy
Version 2.19 of the Salesforce Backup managed package now supports some read-only objects, including History associated objects and more Activities objects. Add these objects to your policy when you want to retain records for future auditing purposes such as reviewing changes to important fields over time.
https://help.salesforce.com/s/articleView?id=release-notes.rn_security_bar.htm&release=250&type=5
Security, Identity, and Privacy
External Client App Manager, OAuth 2.0 token exchange handlers, and Event Log File Browser are each now available in Setup. Also, external client apps now support a bunch of new OAuth flows. Give users access to manage custom domains with a new, more targeted user permission. Create uninterrupted user experiences across Salesforce and custom interfaces with the new Single-Access UI Bridge API. Access your Data Cloud encryption policy status from the Security Center Encryption Policy metric. Scratch orgs on Salesforce Edge Network use partitioned domains. And Android mobile connected apps now require the Admin SDK private key and project ID from a Google Firebase project.
- Salesforce Backup
Salesforce Backup managed package expands the list of supported objects to cover read-only objects. Choose when your backups run with new customizable backup scheduling. - Domains
Update references to legacy Salesforce URLs before redirections stop in Winter ’25. Give users access to manage custom domains with a new, more targeted user permission. And scratch orgs on Salesforce Edge Network use partitioned domains. - Identity and Access Management
Use the External Client App Manager in Setup to create and manage external client apps, and check out the new flows for external client apps. Also in Setup, define and enable OAuth 2.0 token exchange handlers for the OAuth 2.0 token exchange flow. Create uninterrupted user experiences across Salesforce and custom interfaces with the new Single-Access UI Bridge API. - Privacy Center
Review recent changes to Privacy Center’s user interface and functionality. - Salesforce Shield
Encrypt more Nonprofit Cloud data. Net Zero Cloud objects are compatible with Field Audit Trail. Event Log File Browser is generally available for easy access to event log files right from Setup. And say goodbye to third-party tools for digging into event logs. Event Monitoring’s new event log object framework (beta) captures event data in standard objects that support direct queries via API. - Security Center
View pertinent data with enhanced charts. Access your Data Cloud encryption policy status from the Security Center Encryption Policy metric. Create custom metrics (beta) in Security Center. - Other Security Changes
To prepare for two release updates, view blocked redirections and resources in an updated Setup page. Reduce emails about certificate expirations, and create certificates with a 3072-bit key length. And refresh Named Credentials access tokens based on non-standard HTTP status codes.
Security, Identity, and Privacy (salesforce.com)
The Twitter Connector Has Been Retired
Because X (formerly Twitter) has enacted changes to its API terms, the Twitter connector for Account Engagement is no longer available as of October 31, 2023.
Where: This change applies to all Account Engagement editions.
The Twitter Connector Has Been Retired (salesforce.com)
Record Access Is Secure by Default after Enabling Digital Experiences
In Salesforce orgs created on February 8, 2024 or later, after you enable digital experiences, records shared with the Roles and Internal Subordinates group through sharing rules or other features remain accessible only to those internal users. In orgs created before February 8, 2024, records shared with internal users are still made available to external site users automatically, and you must use the Convert External User Access wizard to secure access.
Where: This change applies to Aura, LWR, and Visualforce sites accessed through Lightning Experience and Salesforce Classic in Enterprise, Performance, Unlimited, and Developer Editions.
Why: For orgs created before February 8, 2024, the previous behavior is applied when you enable digital experiences, so that records shared with the Roles and Subordinates group are automatically shared with Roles, Internal and Portal Subordinates. To secure your org’s data, you must remove access for external users with the Convert External User Access wizard and manual updates.
Record Access Is Secure by Default after Enabling Digital Experiences (salesforce.com)
Built-In Salesforce-Managed App for the Twitter Authentication Provider Is Being Retired
The Salesforce-managed app for the Twitter authentication provider is being retired in Spring ’24. To ensure that your users can still log in to your Experience Cloud site via single sign-on (SSO) with X (formerly known as Twitter), update your authentication provider configuration.
Where: This change applies to LWR, Aura, and Visualforce sites accessed through Lightning Experience and Salesforce Classic in Enterprise, Performance, Unlimited, and Developer editions.
Built-In Salesforce-Managed App for the Twitter Authentication Provider Is Being Retired
Identity and Access Management Enhancements for Experience Cloud
For Salesforce Customer Identity, take advantage of security and usability updates and a new authorization flow.
Where: These changes apply to LWR, Aura, and Visualforce sites accessed through Lightning Experience and Salesforce Classic. Most of the changes are available in Enterprise, Performance, Unlimited, and Developer editions, except for the update to headless identity flows, which is available only in Enterprise, Unlimited, and Developer editions.
Identity and Access Management Enhancements for Experience Cloud (salesforce.com)
Prepare for Upcoming CSP Changes
To help prevent code injection attacks, Salesforce plans to update the system-defined trusted URLs that define your site’s content security policy (CSP) in Winter ’25. Prepare for this change by reviewing the impacted resources and updating your trusted URLs.
Where: This change applies to Aura, LWR, and Visualforce sites accessed through Lightning Experience and Salesforce Classic in Enterprise, Performance, Developer, and Unlimited editions.
Prepare for Upcoming CSP Changes (salesforce.com)
Security and Sharing
Prepare for updates to format requirements for trusted URLs that define your site’s content security policy, which are designed to help prevent code injection attacks. Learn about security and usability updates and a new authorization flow for Salesforce Customer Identity. The Salesforce-managed app for the Twitter authentication provider is no longer supported.
- Prepare for Upcoming CSP Changes
To help prevent code injection attacks, Salesforce plans to update the system-defined trusted URLs that define your site’s content security policy (CSP) in Winter ’25. Prepare for this change by reviewing the impacted resources and updating your trusted URLs. - Identity and Access Management Enhancements for Experience Cloud
For Salesforce Customer Identity, take advantage of security and usability updates and a new authorization flow. - Built-In Salesforce-Managed App for the Twitter Authentication Provider Is Being Retired
The Salesforce-managed app for the Twitter authentication provider is being retired in Spring ’24. To ensure that your users can still log in to your Experience Cloud site via single sign-on (SSO) with X (formerly known as Twitter), update your authentication provider configuration. - Record Access Is Secure by Default after Enabling Digital Experiences
In Salesforce orgs created on February 8, 2024 or later, after you enable digital experiences, records shared with the Roles and Internal Subordinates group through sharing rules or other features remain accessible only to those internal users. In orgs created before February 8, 2024, records shared with internal users are still made available to external site users automatically, and you must use the Convert External User Access wizard to secure access.
Security and Sharing (salesforce.com)