Make a Private Connection with Named Credentials
Configure named credentials with an outbound network connection so that API traffic to an AWS account is privately routed and doesn’t traverse the public internet. This feature has been added to non-legacy credentials.
Where: This change applies to Lightning Experience and Salesforce Classic in all editions.
How: When creating a named credential from the UI, select Outbound Network Connection to use a private connection. You can also use the Metadata, Tooling, and Apex ConnectApi APIs to create and edit named credentials.
Make a Private Connection with Named Credentials (salesforce.com)
Use OAuth JWT Bearer Flow with Named Credentials
Configure external credentials that use the OAuth protocol to use JWT Bearer Flow. JWT Bearer Flow provides increased security for system integrations by employing a JSON Web Token (JWT) and certificates to sign requests. Salesforce named credentials support custom claims with JWT Bearer Flow.
Where: This change applies to Lightning Experience and Salesforce Classic in all editions.
How: When creating an external credential from the UI, select JWT Bearer Flow. You can also use the Metadata, Tooling, and Apex ConnectApi APIs to create and edit external credentials.
Use OAuth JWT Bearer Flow with Named Credentials (salesforce.com)
Use AWS Roles Anywhere with Named Credentials
External credentials that employ the AWS Signature v4 protocol can now use Amazon’s Roles Anywhere service to secure AWS integrations via certificates. With Roles Anywhere for named credentials, it’s not necessary for AWS administrators to create IAM Users and store their keys in Salesforce.
Where: This change applies to Lightning Experience and Salesforce Classic in all editions.
How: When creating an external credential from the UI, select Roles Anywhere (Assume an IAM Role via Certificate). You can also use the Metadata, Tooling, and Apex ConnectApi APIs to create and edit external credentials.
Use AWS Roles Anywhere with Named Credentials (salesforce.com)
Enable Content Sniffing Protection (Release Update)
Help shield your org and network from malicious attacks with content sniffing protection. This change helps prevent the browser from loading scripts disguised as other file types when your users access external content and websites from Salesforce. This update was first made available in Winter ’23 and was scheduled to be enforced in Spring ’23, but we postponed the enforcement date to Summer ’23.
Where: This change applies to Lightning Experience and Salesforce Classic in all editions.
When: Salesforce enforces this update in Summer ’23. To get the major release upgrade date for your instance, go to Trust Status, search for your instance, and click the maintenance tab.
Why: Content sniffing is the practice of using the content within a file to automatically determine the file’s Multipurpose Internet Mail Extensions (MIME) type. This process is also called media type sniffing or MIME sniffing, and it can help websites display content with missing or incomplete metadata.
In a cross-site scripting (XSS) attack, an attacker includes malicious code in a client-side script within a legitimate web page or web application. With content sniffing, these malicious files can be misidentified and delivered to the user’s browser.
When you enable content sniffing protection, the X-Content-Type-Options: nosniff HTTP header is added to all pages in Salesforce. This change prevents external content accessed from Salesforce from loading unless the server provides metadata for the resource.
How: To review this update, from Setup, in the Quick Find box, enter Release Updates, and then select Release Updates. For Enable Content Sniffing Protection, follow the testing and activation steps.
To test the effect of this release update, from Setup, in the Quick Find box, enter Session Settings, and then click Session Settings. Select Enable Content Sniffing protection and save your changes. Then test external links and embedded content. In particular, focus on external links that you added, such as hyperlinks and embedded content on custom Visualforce pages.
Enable Content Sniffing Protection (Release Update) (salesforce.com)
Other Security Changes
Increase the security of your named credentials with new configurations. To guard against attacks, content sniffing protection is enforced, and we recommend that you review your clickjack protection settings.
- Enable Content Sniffing Protection (Release Update)
Help shield your org and network from malicious attacks with content sniffing protection. This change helps prevent the browser from loading scripts disguised as other file types when your users access external content and websites from Salesforce. This update was first made available in Winter ’23 and was scheduled to be enforced in Spring ’23, but we postponed the enforcement date to Summer ’23. - Use AWS Roles Anywhere with Named Credentials
External credentials that employ the AWS Signature v4 protocol can now use Amazon’s Roles Anywhere service to secure AWS integrations via certificates. With Roles Anywhere for named credentials, it’s not necessary for AWS administrators to create IAM Users and store their keys in Salesforce. - Use OAuth JWT Bearer Flow with Named Credentials
Configure external credentials that use the OAuth protocol to use JWT Bearer Flow. JWT Bearer Flow provides increased security for system integrations by employing a JSON Web Token (JWT) and certificates to sign requests. Salesforce named credentials support custom claims with JWT Bearer Flow. - Make a Private Connection with Named Credentials
Configure named credentials with an outbound network connection so that API traffic to an AWS account is privately routed and doesn’t traverse the public internet. This feature has been added to non-legacy credentials. - Review Your Clickjack Protection Settings
Clickjacking uses a trusted domain or site to trick users into clicking a malicious link. The trusted domain is served in an iframe, then a hidden or transparent UI control is served in the same location. To help protect against this kind of attack, learn more about clickjacking and the Salesforce page types that can be framed. Then review your clickjack settings.
Other Security Changes (salesforce.com)
Get Improved Unique Field Masking
Pattern masking values that are marked unique and greater than their field length are now shortened differently to ensure data integrity. Previously, the custom pattern value was shortened before the record ID to meet the maximum field length. Now the appended record ID is shortened before the pattern value. If the field value is still too long after the record ID is shortened, you’re prompted to edit your custom pattern value to ensure uniqueness.
Where: This change applies to Lightning Experience in Enterprise and Unlimited editions.
Get Improved Unique Field Masking (salesforce.com)
Process Data Mask Jobs Faster
Spend less time waiting and more time masking your sandbox data with improved processing times. We removed the batch preparation step, so your Data Mask jobs finish faster.
Where: This change applies to Lightning Experience in Enterprise and Unlimited editions.
When: See faster processing times starting on April 11, 2023.
Who: This product is available to users with the Data Mask managed package.
Process Data Mask Jobs Faster (salesforce.com)
Data Mask
Use Data Mask to obfuscate sensitive information in your sandbox so that data isn’t replicated in a readable or recognizable way in another environment. Faster job processing times and improvements to unique field masking are headed your way.
- Process Data Mask Jobs Faster
Spend less time waiting and more time masking your sandbox data with improved processing times. We removed the batch preparation step, so your Data Mask jobs finish faster. - Get Improved Unique Field Masking
Pattern masking values that are marked unique and greater than their field length are now shortened differently to ensure data integrity. Previously, the custom pattern value was shortened before the record ID to meet the maximum field length. Now the appended record ID is shortened before the pattern value. If the field value is still too long after the record ID is shortened, you’re prompted to edit your custom pattern value to ensure uniqueness.
Evaluate Data Quickly with Insightful Data Labels
Analyze charts within the Configuration metric category with new and improved data labels.
Where: This change applies to Enterprise, Performance, Unlimited, and Developer editions where Security Center is available.
Who: This change is available to users with the Security Center add-on subscription.
How: From Security Center, select the Configuration metric category from the Security Overview menu on the left.
Evaluate Data Quickly with Insightful Data Labels (salesforce.com)
Execute CRM Analytics Features on Security Center Data
Use CRM Analytics to build out dashboards based on your use cases and to report on Security Center data. To execute CRM Analytics features on relevant data, connect to Security Center objects.
Where: This change applies to Enterprise, Performance, Unlimited, and Developer editions where Security Center and CRM Analytics are available.
Who: This change is available to CRM Analytics users with the Security Center add-on subscription.
How: From Data Manager, click Connections. From the All Connections page, click New Connection, then Salesforce Connector. Fill out the required fields and search for TenantSecurity to set up the connection to Security Center objects.
Execute CRM Analytics Features on Security Center Data (salesforce.com)