Extend User Sessions for High Volume Customer Portal Users (Beta)

Make it easy for users with the High Volume Customer Portal user license to stay logged into your site. Keep users logged in for up to 7 days of inactivity, and allow them to remain logged in even after they close their browser.

Where: This change applies to Lightning Experience and Salesforce Classic in Enterprise, Performance, Unlimited, and Developer editions.

How: In profile session settings, select a timeout value for Session Times Out After, and select Keep users logged in when they close the browser.

Extend User Sessions for High Volume Customer Portal Users (Beta) (salesforce.com)


Get Information About Named Credentials in the EventLogFile

Capture information about Apex callouts that use named credentials as their endpoints with the EventLogFile object’s new Named Credential event type. This event type is ideal for auditing the installed managed packages that use named credentials.

Where: This change applies to Enterprise, Performance, Unlimited, and Developer editions. This event is available in the API but not in the Event Monitoring Analytics app.

Get Information About Named Credentials in the EventLogFile (salesforce.com)


Email and SMS One-Time Password Codes Are Longer

To improve security, we increased the length of one-time passwords (OTPs), also known as verification codes, from five digits to six. This change applies to OTPs sent through email and SMS. If you have customizations that rely on five-digit OTPs, such as Apex implementations for multi-factor authentication or passwordless login, make sure you update them.

Where: This change applies to Lightning Experience and Salesforce Classic (not available in all orgs) in all editions.

Email and SMS One-Time Password Codes Are Longer (salesforce.com)


Identity Cookies Have Shorter Durations

To improve privacy, we shortened the lloopch_loid cookie duration from 2 years to 1 year. And we changed the duration of the hideIdentityDialog cookie from 50 years to 1 year.

Where: This change applies to Lightning Experience and Salesforce Classic in all editions.

Identity Cookies Have Shorter Durations (salesforce.com)


Control the Language Used for Experience Cloud Self-Registration Verification Messages

To give you more control over email and SMS verification messages, we changed how the initSelfRegistration method detects a user’s language. You can now specify a language in the User object to guarantee that verification messages use the correct language.

Where: This change applies to Aura, LWR, and Visualforce sites accessed through Lightning Experience and Salesforce Classic in Enterprise, Performance, Unlimited, and Developer editions.

Control the Language Used for Experience Cloud Self-Registration Verification Messages (salesforce.com)


Tailor Device Activation Emails for Experience Cloud Sites

Take control of your customer communications with the Device Activation email template. You can use the template to customize the emails your users receive when they log in from an unfamiliar browser, app, or location.

Where: This change applies to Aura, LWR, and Visualforce sites accessed through Lightning Experience and Salesforce Classic in Enterprise, Performance, Unlimited, and Developer editions.

Tailor Device Activation Emails for Experience Cloud Sites (salesforce.com)


Salesforce Identity for Your Customers

Maintain consistent branding for your site and control customer communications with the Device Activation email template. When you’re using Apex to manage identity verification for Experience Cloud sites, guarantee that self-registration verification messages are sent in the right language. To improve privacy and security, we shortened durations of the lloopch_loid and hideIdentityDialog cookies and increased the length of one-time passwords.

  • Tailor Device Activation Emails for Experience Cloud Sites
    Take control of your customer communications with the Device Activation email template. You can use the template to customize the emails your users receive when they log in from an unfamiliar browser, app, or location.
  • Control the Language Used for Experience Cloud Self-Registration Verification Messages
    To give you more control over email and SMS verification messages, we changed how the initSelfRegistration method detects a user’s language. You can now specify a language in the User object to guarantee that verification messages use the correct language.
  • Identity Cookies Have Shorter Durations
    To improve privacy, we shortened the lloopch_loid cookie duration from 2 years to 1 year. And we changed the duration of the hideIdentityDialog cookie from 50 years to 1 year.
  • Email and SMS One-Time Password Codes Are Longer
    To improve security, we increased the length of one-time passwords (OTPs), also known as verification codes, from five digits to six. This change applies to OTPs sent through email and SMS. If you have customizations that rely on five-digit OTPs, such as Apex implementations for multi-factor authentication or passwordless login, make sure you update them.
  • Get Information About Named Credentials in the EventLogFile
    Capture information about Apex callouts that use named credentials as their endpoints with the EventLogFile object’s new Named Credential event type. This event type is ideal for auditing the installed managed packages that use named credentials.
  • Extend User Sessions for High Volume Customer Portal Users (Beta)
    Make it easy for users with the High Volume Customer Portal user license to stay logged into your site. Keep users logged in for up to 7 days of inactivity, and allow them to remain logged in even after they close their browser.

Salesforce Identity for Your Customers


OAuth 2.0 User-Agent Flow Supports mobileauth.salesforce.com/analytics Redirect URL for Refresh Tokens

The OAuth 2.0 user-agent flow now supports refresh tokens when the scope=refresh_token is included in the request and the redirect URL is https://mobileauth.salesforce.com/analytics/oauth/done.

Where: This change applies to Lightning Experience and Salesforce Classic in all editions.

OAuth 2.0 User-Agent Flow Supports mobileauth.salesforce.com/analytics Redirect URL for Refresh Tokens


Give Authorized Access to Salesforce CDP Data

To authorize additional access to Salesforce CDP data, you can assign a connected app two new OAuth scopes. With the Perform ANSI SQL queries on Salesforce CDP data OAuth scope, the connected app can perform ANSI SQL queries of Salesforce CDP data on behalf of the user. The Manage Salesforce CDP profile data OAuth scope gives the connected app access to Salesforce CDP REST API data to manage profile records.

Where: This change applies to Lightning Experience and Salesforce Classic (not available in all orgs) in Group, Professional, Enterprise, Essentials, Performance, Unlimited, and Developer editions. Connected apps can be installed in all editions.

How: Assign the OAuth scopes to the connected app that represents your external app.

Give Authorized Access to Salesforce CDP Data


Upgrade to Identity Connect 7.1.1

Identity Connect 7.1.1 offers extensive security enhancements. As of the Winter ’22 release, you can no longer download Identity Connect 2.1 and Identity Connect 3.0.X.X. We recommend that you upgrade to Identity Connect 7.1.1 as soon as possible.

Where: This change applies to Lightning Experience and Salesforce Classic and is available for an additional cost in Enterprise, Performance, and Unlimited editions. Developer edition includes 10 Identity Connect permission set licenses.

How: To install Identity Connect 7.1.1, use the download link on the Identity Connect setup page. Before you upgrade from Identity Connect 2.1 or 3.0.X.X, make sure that you have the latest version of the Identity Connect managed package installed.

Upgrade to Identity Connect 7.1.1 (salesforce.com)


Privacy Preference Center