Skip to main content

#Security Settings0 diskutieren mit

Hi All,

 

I wanted to know that if I enable the session setting "Lock sessions to the domain in which they were first used" what could be the impact of it ?

 

I am able to access SF(Client domain) data using standard API via POSTMAN(locally setup).

 

Kindly suggest, Any scenarios where in we have to keep this setting disabled ?

 

#Security #Security Specialist #TrailblazerCommunity #Security Settings #AwesomeAdmins

1 Antwort
0/9000

How to resolve deployment of Security Settings metadata throwing error: canUsersGrantLoginAccess

 

I was trying to figure out what was causing the non-explanatory error on deploying the security settings metadata file. 

 

The issue surfaced, when I switched the deploying user from having the standard System Admin profile to a custom Minimum Access profile with added permissions on top. 

 

The solution was to grant the deploying user the system permission of Manage Login Access Policies. Once this permission was granted, then the deploying user was no longer facing the problem. 

 

#Deployment Error  #Metadata  #Security Settings

0/9000

I'm working on the Security Superbadge so that I can get the security settings straight in my head. Does anyone else have trouble finding things when you have the Enhanced Profile User Interface on (or off)?

 

For IP ranges, I could not find that setting at all with the Enhanced Profile User Interface disabled.

 

Conversely, when the Enhanced Profile User Interface was enabled, I could not figure out how to enable the mobile settings.

 

Some of this seems like it's designed to confuse! Settings seem to disappear depending on what setting this is on. 

5 Kommentare
  1. 16. Okt. 2022, 19:16

    Hi Eileen.. Can you please tell me how to enable Enhanced Profile User Interface?

0/9000

Hello everyone, 

 

I understand settings like Enable clickjack protection for setup pages / non setup pages are default enabled and can't be modified by Admin.

 

But Is there any valid scenario exists when we have to uncheck these settings ?

 

Kindly suggest.

 

Thanks   #Security Settings #Security #Salesforce Admin #TrailblazerCommunity

4 Antworten
  1. 4. Okt. 2021, 10:36

    Hi @Archana Panda

     

    Yes surely it did help, but still I am not getting clear understanding in which scenario we have to keep this setting disabled.

0/9000

What happened to the Enable HSTS for all Sites and Communities with the default force.com subdomain that require a secure connection (HTTPS) setting?  Is not in Session Setting.

 

this link talks about HSTS but where is the setting??

 

#Security Settings

https://help.salesforce.com/s/articleView?id=sf.browser_security.htm&type=5

1 Antwort
0/9000

I want to have a profile for certain users to be able to have access to edit User records and literally nothing else. Whats the easiest way to do this ? View setup + Manage Internal Users permissions?

 

 Ideally wouldn't be able to view the rest of setup but don't think thats possible?

 

Thansk

 

#Security Settings

1 Antwort
  1. 10. Aug. 2021, 09:45

    create a profile or permission set as per your need

0/9000

Why there are so many settings

Sharing settings

Permission Sets

Permission Set groups

User Management Settings

Field level Settings, Object Level Settings, Role wise Profile wise,recordwise(owd,manual sharing) etc

Why all these are segregated here and there . why there is no one stop for all ?

#Data Security #Security Settings #Data Security Module #Salesforce Administrator #Salesforce Update

0/9000

If a record owned by a specific user ,Is it always possible to edit a record ,user above  that specific user in Role hierarchy by default?

 

#Security #Security Predicates #Security Settings #Security Key #Security Specialist #Security Controls #Salesforce #Salesforce Admin #Sales Cloud

1 Antwort
  1. 11. Juli 2021, 10:43

    Hi Abdul,

    If the "Grant Access Using Hierarchies" option is deselected on any object in sharing settings, users that are higher in the role or territory hierarchy don’t receive automatic access. However, some users—such as those with the “View All” and “Modify All” object

    permissions and the “View All Data” and “Modify All Data” system permissions—can still access records they don’t own.

     

    Hope this helps!

     

    Stay Safe

0/9000

The password reset policy states the password would expire in 60 days. But my users have not changed or don't receive any password reset for more than 60 days. Any pointers on how to see if this 60days policy is followed #Reports & Dashboards #Salesforce Administrator #Security Settings

6 Antworten
0/9000

Hi All @* Salesforce Administrators * 

 

Can anyone tell me which security settings override all the security settings based on Profiles, permissions sets, OWD, Field Accessibility?

 

Thanks in Advance

Rakshita

6 Kommentare
0/9000