Skip to main content

#Security155 personnes en discutent

UPDATE: I spoke to support, and apparently the list view was for backend purposes and was not supposed to be visible. It was not reflecting any actual scan of the files, and we seem to be fine in that regard. I was told that if I can't see the Malicious Files list in the Files app from the App Launcher directly, then there are no files flagging as malicious. 

 

Good morning! 

 

Yesterday I noticed that Salesforce had rolled out this 'Malicious Files' list view, but it seems to be listing most, if not all, of our files as malicious (for context, they are largely just regular PDFs uploaded by me to attach to opportunities for backup & documentation). Does anyone know what is causing these to be in this list view? Is there a different way to upload files that I should be using?  

 

Thank you for your help. 

 

#Salesforce Admin  #Security

3 réponses
  1. 4 sept., 04:47

    The update clarifies that the Malicious Files list view was a backend/internal view and was not actually indicating that those PDFs had failed a malware scan. 

    If the Malicious Files list isn't visible in the Files app from the App Launcher, Salesforce Support indicated that there are no files currently flagged as malicious. 

    So this appears to be a Salesforce UI/list-view issue rather than an issue with how the PDFs were uploaded

    .  

     

0/9000

Business Requirement    HR users can access all Employee records.    Managers should only see Employees in their own Location.    

2 réponses
  1. 4 sept., 04:34

    Hi @Rohit .

     

    Restriction Rules alone won’t satisfy this requirement, as they can only restrict existing access, not grant access.  

     

    A better approach would be: 

    •  Set OWD to Private for Employee. 
    •  Give HR users access to all Employee records using appropriate sharing or View All permission. 
    •  Give Managers access to employees in their own Location using criteria-based sharing or Apex Managed Sharing for dynamic requirements. 

    Use sharing mechanisms to grant access, and Restriction Rules only when additional record-level restriction is required. 

     

    Hope This Helps!! 

0/9000

A multinational company has:    Sales  HR  Finance  Support  Legal    Across:    USA  UK  India  Australia    Requirements:    Country-wise record visibility.  Managers see subordinate records.  HR records are confidential.  Legal sees high-value Opportunities.  Finance has read-only access.  Partners see only their own data.  CEO sees everything.  Temporary access for auditors.    

2 réponses
  1. 4 sept., 04:47

    Hi @Rohit ., 

     

    A suitable Salesforce security approach would be:  

     

    • Country-wise visibility: Use OWD + Roles/Sharing Rules to control access by country. 
    • Managers: Use the Role Hierarchy so managers can access subordinate records. 
    • HR: Keep HR records restricted using Private OWD + Restriction Rules/Sharing as required. 
    • Legal: Provide access to high-value Opportunities through Criteria-Based Sharing Rules. 
    • Finance: Assign a Read-Only Permission Set/Profile. 
    • Partners: Use Experience Cloud with appropriate sharing sets/rules so partners see only their own records. 
    • CEO: Place the CEO at the top of the Role Hierarchy with appropriate access. 
    • Auditors: Provide temporary access through appropriate permission sets and sharing, with access removed after the audit. 

     

    This follows the Salesforce security model by combining OWD, Role Hierarchy, Sharing Rules, Restriction Rules, Profiles/Permission Sets, and Experience Cloud sharing based on each requirement. 

     

    Hope This Helps!! 

0/9000
3 réponses
  1. 3 sept., 17:14

    Hi @Rohit .

     

     

    You can handle this using a

    Validation Rule on Opportunity. The rule can check whether the Opportunity was already Closed Won

    and block further updates for Sales Users, while allowing specific users such as System Administrators to edit it.  

     

    This is generally a better approach than relying only on page layout settings, because the validation rule enforces the restriction when the record is saved.  

     

    Hope this helps! 

0/9000

Restriction Rules  Business Requirement    HR users can access all Employee records.    Managers should only see Employees in their own Location.      

5 réponses
  1. 3 sept., 11:08

    @Hitesh Sharma  

    Yes. A single Restriction Rule can apply to multiple Managers. You don't need one rule per user. 

    Use a shared attribute such as Location and make the rule apply to the Manager group/role, for example: 

    User.Location__c = Employee.Location__c

      

    Then all 10 Managers can use the same rule, provided each Manager has their own Location value. 

      

    HR users:

    excluded from the restriction, so they can see all Employee records. 

     

    So the design is: 

     

    1 Restriction Rule → 10 Managers → each sees only Employees matching their Location.

     

     

0/9000

 

hello , i forgot my password and my security question , is there a way to retrieve the password or change it ? 

 

#Security

2 réponses
  1. 1 sept., 16:03

    Hi Salma, 

     

    This community can't reset passwords or security questions directly — that has to go through the proper account recovery channel. Which one applies depends on what kind of account this is: 

     

    1. Trailhead/Trailblazer account: Go to

    https://login.salesforce.com or the Trailhead login page and click "Forgot Your Password?" — it'll email a reset link to the address on file. If you no longer have access to that email either, you'll need to submit a case via Trailhead Help: https://trailhead.salesforce.com/help?support=home

     

     

    2. A company/work Salesforce org: Only your org's Salesforce Administrator can reset your password and security question for you — this can't be self-served or done by Salesforce Support directly, since it's your employer's org, not a personal account. 

     

0/9000

Hey Folks, 

 

We have a couple of contractors that are having issues creating passkeys for the upcoming phishing resistant mfa for privileged users update. Thus far, all the regular employees using company issues devices are having having any problems. For these two, one uses a mac and the other uses a virtual windows machine. Because of this, we believe this may be the problem. Does anyone have any experience creating passkeys with these cases? 

 

#Security  #MFA  #PhishingResistantMFA

2 réponses
  1. 1 sept., 13:20

    For anyone with this same question - SF support has stated that virtual machines are exempt from this requirement. We did observe this as I was prompted to create a passkey when logging into the environment but the user with the VM was not prompted when they logged in to the same env.

0/9000

Suppose we have 3 users in the same role hierarchy:

Manager → Team Lead → Executive

The OWD for Opportunity is Private.

Now consider:

  • The Executive owns an Opportunity.
  • The Team Lead has Read access through a Permission Set.
  • The Manager has View All on the Opportunity object.
  • The Executive's Salary field is hidden from the Team Lead using Field-Level Security.
  • The Manager can see all Opportunity records, but should not be able to see the Salary field.

Question:

If the Manager has View All

permission on Opportunity, does that automatically allow the Manager to see every field on the Opportunity record, including the Salary field? 

 

#Security

7 réponses
  1. 1 sept., 06:10

    Hi @Pranjal Budhlakoti, 

     

    Adding On 

    @Hitesh Sharma & @Rohit .

     

    No, View All does not automatically give access to every field on an Opportunity.

    View All is a record-level permission. It allows the Manager to view all Opportunity records, regardless of OWD, sharing rules, role hierarchy, or ownership. 

     

    However, Field-Level Security (FLS) controls whether the Manager can see or edit specific fields. Therefore, if the Salary field is hidden from the Manager through FLS, the Manager will not be able to see that field even though they have View All on Opportunity.

    In this scenario:

    • OWD = Private → controls baseline record access.
    • View All → Manager can view all Opportunity records.
    • FLS → still controls visibility of individual fields.
    • View All does not override FLS.

    So the key point is: Record-level permissions and field-level permissions work independently. 

0/9000

 It just started today, 7/22, that when staff export reports, they are asked for verification code. 

When they enter the code from the authentication app, it doesn't work and just keep looping. 

I tried to generate temporary verification code via staff's user account. An email was sent to them but no code and no link, nothing. I don't have the code either. so dead-end. 

 

We use MS SSO for staff to get in Salesforce. Our IT people just enabled passkey method on the network. One staff set up passkey successfully and she could now export reports fine. However, two other staff can't set up passkey, the same, got stuck on verification code screen. 

 

I don't know what else to do. Please advise. 

9 réponses
  1. 31 août, 17:33

    @Max Wilson I don't think so.  Are you the Salesforce Sys Admin or are you a user and trying to get info for the admin?  I'm happy to help if you can tell me more.

0/9000

Hi All, 

 

Have any of you had any reports of the SF Authenticator app sending approval prompts even when a User is not trying to log in? 

 

I have now had two reports of this behaviour and I am unsure what to do. The login and session mgmt logs are not telling me anything. 

 

Is it enough to have them uninstall/reinstall the app and disconnect on their User record? 

 

Any insight would be helpful! Thanks!! 

 

#Security  #TrailblazerCommunity  #Salesforce Admin  #Salesforce

2 réponses
  1. 31 août, 13:59

    Hi Eric, Thanks for the thought. I have already done so and there is nothing suspicious.

    Carolyn

0/9000