Skip to main content

#TrailblazerCommunity191 utenti parlano di questo argomento

In salesforce revenue cloud. I am facing an issue in Cardinality. 

GrandParent Product(Bundle) -> Parent Product (Bundle) -> Child Product. 

I want the cardinality of all the 3 products via CML. 

Is there any possibility? 

 

 

#Salesforce Revenue Cloud  #Salesforce Developer  #Trailhead Challenges  #Trailhead  #TrailblazerCommunity

0/9000

Hi everyone,

I’m working on social media content workflows and I’m trying to understand how other teams manage Instagram video assets when they need to reuse them in Marketing Cloud campaigns.

For example, a short Instagram video may later be needed for an email campaign, landing page, or another marketing asset. Do you normally keep these files in a dedicated DAM or cloud storage system, or do you manage them directly through Content Builder?

I’m especially interested in the workflow for keeping the original video quality, organizing different versions, and avoiding duplicate files.

For smaller Instagram workflows, I’ve also come across browser-based tools such as Indown.mobi, but I’m mainly interested in how Salesforce users structure the overall media-management process.

What approach has worked best for your team? 

 

#TrailblazerCommunity

1 risposta
  1. Ieri, 08:50

    Hi Riggins,

     

    The industry consensus across enterprise Salesforce teams is clear: do not use Marketing Cloud Content Builder as your primary video asset library.

     

    Content Builder is designed for lightweight email/web assets (images, logos, HTML snippets, and documents), not for source-quality video management or social asset version control.

     

    Here is the standard, scalable architecture most marketing teams use to bridge Instagram video content with Marketing Cloud:

     

    1. Centralize Master Videos in a DAM or Cloud Storage (Single Source of Truth)

    Never rely on re-downloading videos from Instagram (using browser downloaders or scrapers) for cross-channel campaigns. Instagram compresses videos aggressively upon upload, degrades the bitrate, and removes metadata.

     

    • Dedicated DAM / Enterprise Cloud: Use a Digital Asset Management platform (e.g., Bynder, Brandfolder, Adobe Experience Manager) or enterprise cloud storage (Google Drive, AWS S3, SharePoint).

     

    • Store Raw Masters: Keep the high-resolution source video (.mp4 / .mov in 1080p/4K, 9:16 vertical and 1:1 square formats) in the DAM before it gets posted to Instagram.

     

    • Naming & Tagging Taxonomy: Standardize naming conventions (e.g., YYYYMM_Campaign_Concept_Format_v01.mp4) and tag assets by platform, campaign, and rights clearance to eliminate duplicate uploads.

     

    2. Hosting & Video Delivery for Marketing Cloud

    Marketing Cloud Content Builder has file-size upload limits (typically 20 MB max for generic media files), which is too restrictive for high-quality video files.

     

    • Host Externally on a CDN or Video Platform:
      • Host videos on a dedicated video streaming service (e.g., Vimeo Enterprise, Wistia, YouTube, or a custom CDN/CloudFront).
      • For CloudPages / Landing Pages: Embed the responsive player (<iframe> or HTML5 <video> tag pointing to the CDN URL). This ensures adaptive bitrate streaming across mobile and desktop without taxing Content Builder bandwidth.

     

    3. How to Render Instagram Video in Marketing Cloud Emails

    Direct video embedding (<video> tags) in email has notoriously spotty support across email clients (Outlook, Gmail, and Yahoo generally block or fail to render inline video players).

     

    • The Pseudo-Video Pattern (Best Practice):
      1. Generate an animated GIF of the best 3–5 seconds from the Instagram video (optimized under 1–2 MB).
      2. Alternatively, create a high-res still thumbnail with a semi-transparent "Play Button" icon overlaid in the center.
      3. Upload that thumbnail/GIF into Content Builder.
      4. Hyperlink the image to your Marketing Cloud CloudPage, website landing page, or Instagram post where the full-quality video lives.

     

    • This delivers near-100% email client compatibility, loads instantly, and drives high click-through rates.
0/9000
Lena Wong ha fatto una domanda in #Trailhead

Hi everyone,

I’m experiencing a persistent WebAuthn loop during MFA setup in one specific Salesforce organization, and I’d really appreciate the community’s technical insight into what could be causing the discrepancy.

 

I have two independent Salesforce environments running on the same Windows 11 laptop and using the same browsers (Chrome/Edge). 

 

Org A 

Everything works as expected:

  • When I go to Advanced User Details → Built-In Authenticators → Add, Windows Security displays the native “Sign in with a passkey” prompt.
  • It correctly recognizes the credential for my Salesforce user.
  • The credential is associated with the expected Salesforce domain 
  • I can authenticate immediately using my local Windows Hello PIN.

Org B 

The behavior is completely different:

  • Under Advanced User Details → Built-In Authenticators → Add, Windows Security does not offer the local “This Device” / Windows Hello platform authenticator.
  • Instead, it immediately launches the roaming/cross-platform authenticator flow and displays the Mobile Phone / QR-code prompt.
  • Selecting “Choose a different passkey” or “Save another way” does not expose Windows Hello; it simply returns me to the same QR-code flow.
  • As a result, I am effectively stuck in an unskippable WebAuthn registration loop.

Settings already verified in Org B

I have checked the relevant Salesforce configuration and cannot identify an obvious organizational restriction:

  1. Identity Verification Settings 

    “Let users verify their identity with a built-in authenticator (passkey) such as Touch ID or Windows Hello” is explicitly enabled.
  2. Session Security Level Policies 

    Administrative operations, including Profile and Permission Set management, are configured with

    None for High Assurance session step-up requirements.
  3. Browser extensions 

    The Microsoft Authenticator extension is enabled in both environments, so extension differences do not appear to explain the behavior.

I would appreciate any suggestion as I am running in loops and have always to use my iphone to scan a QR Code because Salesforce is asking me for a passkey. I can not use my PIN in Windows Hello. 

 

@Salesforce Administrators & Developers, @Salesforce Administrators and Developers, @APAC Architects

 

 

#Trailhead  #Salesforce Developer  #Salesforce Admin  #TrailblazerCommunity

3 risposte
  1. 16 set, 15:58

    Hi Lena, since both orgs are on the same laptop/browser and your Salesforce config in Org B genuinely looks correct, this is very likely a browser/Windows-side caching issue tied to the different origin (domain), not a Salesforce policy difference. A few things worth checking: 

     

    1. Check Windows' own Passkey manager for a stale entry. Go to Windows Settings → Accounts → Passkeys (or Sign-in options → Passkeys). Look for any existing entry tied to Org B's domain — even a partial/failed registration attempt from earlier can cause Windows to skip the "create new" platform flow and jump straight to the cross-device/roaming flow instead. Delete any entry there for Org B's domain, then retry from Salesforce. 

     

    2. Clear the browser's per-site permissions for Org B's domain. Chrome/Edge cache a "last used transport" preference per relying-party origin. In Chrome: Settings → Privacy and security → Site settings → search for Org B's domain → Clear data/reset permissions. This forces the browser to re-evaluate available authenticators instead of defaulting to whatever you (or a prior session) picked before. 

     

    3. Confirm Org B's My Domain is fully deployed, not just the default login URL. WebAuthn ties credentials to the Relying Party ID (essentially your domain). If Org B is still on a default/undeployed domain or recently changed its My Domain, the RP ID Salesforce sends can differ from what you'd expect, which changes how the browser matches existing/available authenticators. 

     

    4. Try a fully fresh browser profile/incognito window against Org B only, to rule out any extension (you mentioned Microsoft Authenticator extension is on in both — try disabling it just for this test) or cached state interfering specifically with that origin. 

     

    5. As a last resort, use "Disconnect a passkey that isn't working" from your Salesforce personal settings (Advanced User Details → Built-In Authenticators → Del on any existing/broken entry for Org B), then try Add again from a clean state. 

     

    If none of that breaks the loop, this is worth escalating to Salesforce Support directly with both orgs' IDs — a same-device, same-browser, config-identical discrepancy between two orgs isn't something Setup-level settings can explain, and Support can check server-side registration options (like exclude-credential lists) that aren't visible from the UI. 

     

    Reference:

    https://help.salesforce.com/s/articleView?id=005390721&language=en_US&type=1

0/9000

#Trailhead  #Automation #TrailblazerCommunity #Trailblazers #Analytics

There is a request from an internal team at the organization to send a report extract from Salesforce to a shared network drive within the organization for a bot to pickup. Is there a way to automate this within Salesforce? 

1 risposta
  1. 17 set, 14:05

    Hi Rashi,

    Salesforce doesn't natively write files directly to an organization's shared network drive. A common approach is to use an external integration or middleware between Salesforce and the network location.

    For example:

    1. Schedule a Salesforce report/export or query the required records through the Salesforce API.
    2. Have an integration service retrieve the data on a schedule.
    3. The integration writes the generated CSV/file to the shared network drive for the bot to process.

    Depending on your environment, this could be implemented using MuleSoft, an ETL/integration platform, or a small scheduled service that uses the Salesforce API. 

     

    If the requirement is specifically for a scheduled Salesforce report export, rather than querying the data directly, the available options are different. Sharing the required file format, frequency, and whether middleware is already available would help determine the best approach. 

0/9000

Hello everyone, 

 

I’m currently preparing for the Salesforce Certified Platform Foundations exam and am looking for high-quality practice questions to help evaluate my readiness. 

Whether official or third-party, free or paid, I would love to hear which study platforms or practice exams worked best for you. 

 

Thank you so much for your help! 

 

#TrailblazerCommunity

1 risposta
0/9000

B2B commerce visualforce

#SalesforceLive - What promo options are released for visualforce sites?  We cannot use the lightning version of your app.

1 risposta
  1. 16 set, 21:02

    Hi George,

    Could you please share which version of B2B Commerce for Visualforce you're using and what type of promotion functionality you're looking for? 

     

    It would also help to know which Lightning promotion features you need to replicate on the Visualforce site. The available promotion capabilities can depend on the Commerce implementation and package/release version. 

     

    If you can provide those details, someone may be able to confirm which promotion options are supported for your Visualforce implementation. 

0/9000
1 risposta
  1. 16 set, 20:52

     Hi Vinjul,

    If Apex is returning the updated records but the child component is not reflecting them, the issue is likely with how the data is being passed from the parent to the child.

    Could you please share the parent and child component code, especially:

    • The combobox onchange handler
    • The Apex call and how you assign the returned data
    • The @api property used to pass data to the child
    • The child component's HTML/JS where the records are displayed

    Also, make sure you're assigning a new value to the property rather than modifying the existing array/object in place, so the component can detect the change. 

     

    With the relevant code, we can identify exactly where the refresh is getting missed.

0/9000
Scott Holmes ha fatto una domanda in #Trailhead Challenges

I'm getting stumped on this. Org wants to create a push notification for overdue tasks. I have done it using a record-triggered flow with 7 days and 2 days as being notifications email to say Task is about to be due. Could it just be a push notification which stays in Salesforce, notification sent to the notification bell once daily . 

 

#Trailhead Challenges  #Trailhead  #Salesforce Admin  #TrailblazerCommunity  #Sales Cloud  #Formulas

5 risposte
  1. 16 set, 16:35

    Hi @Scott Holmes

     

    Yes, you can check the formula syntax directly in Flow Builder. Formula resources are created within the Flow, so you won't find their syntax in Object Manager.

    To view the syntax:

    1. Open your Flow in Flow Builder.
    2. Go to the Manager tab.
    3. Under Resources, select your Formula resource (Due in 7 Days / Due in 2 Days).
    4. Open the formula to view or edit its syntax.

    For example:

    Due in 7 Days:

    {!$Record.ActivityDate} = TODAY() + 7

    Due in 2 Days:

    {!$Record.ActivityDate} = TODAY() + 2

    You can also review Salesforce's formula documentation for additional functions and syntax. 

     

    Hope this helps!  

     

     If you find this response helpful, please mark it as the Accepted Answer, as it may also help other Trailblazers facing a similar issue. 😊 

0/9000

We make outbound Apex callouts from a named credential to a vendor API. The vendor has moved that API onto a private cloud network, and our callouts now fail at the network layer before auth is ever evaluated. 

 

The only working solution we've found is for the vendor to allowlist Salesforce's published Hyperforce outbound ranges from https://ip-ranges.salesforce.com/ip-ranges.json (per KB 003876184, which explicitly recommends an IP allowlist for outbound Apex callouts since Salesforce outbound IPs may not resolve under *.salesforce.com). 

 

That works, but it has two drawbacks we'd like to avoid: the ranges are shared across all Salesforce tenants on that infrastructure, so it's a weak control rather than a real identity boundary and Salesforce advises allowlisting the entire file, which is a broad and evolving surface for the vendor's security team to accept. 

 

What I'm hoping someone has solved before-- 

 

  1. Salesforce's stated preferred alternatives are mTLS and domain allowlisting, but both assume the far side is filtering at the application layer. When the block is network-level, a client certificate doesn't get you through the firewall. Has anyone actually used mTLS to solve a reachability problem rather than an auth one, or am I right that it's the wrong tool here?
  2. Private Connect / Outbound Network Connection appears to be AWS PrivateLink only. Can anyone confirm whether Azure-hosted targets are supported, now or on the roadmap?
  3. Is there any other mechanism to give an external endpoint a stable or narrower egress identity for Apex callouts?
  4. For those who've hit this: did you end up putting a relay/gateway in front of the private service and pointing Salesforce at that instead? Would you recommend it?

Any experience appreciated, we have a go-live this week, so we're proceeding with the allowlist for now and looking for something more durable after. 

 

Articles that I have already read - 

 

1. https://help.salesforce.com/s/articleView?id=003876184&type=1

2. https://help.salesforce.com/s/articleView?id=000384438&type=1

 

#Salesforce Developer  #Architects  #Solution Architects  #TrailblazerCommunity  #Security  #Integration

1 risposta
  1. 16 set, 15:59

    Hi Piyush, 

     

    1. You're right, mTLS is the wrong tool here. mTLS operates at the application/TLS layer after a TCP connection is already established — it proves identity to something that's already listening and accepting connections. If the vendor's firewall is dropping packets before that handshake even starts, no client cert changes that. mTLS solves "who is this," not "can this even reach me." 

     

    2. Private Connect is AWS PrivateLink-based only, so it's natively usable when the target sits in an AWS VPC. Azure targets aren't natively supported — you'd need inter-cloud private peering (AWS↔Azure via ExpressRoute/Direct Connect + a transit arrangement) which Salesforce doesn't self-serve; that requires your account team and is a heavier lift. No public roadmap confirmation of native Azure PrivateLink support as of now. 

     

    3. No native mechanism gives an Apex callout a narrower/tenant-specific egress identity beyond the published IP ranges — that's the actual gap you've identified. The published Hyperforce ranges are deliberately shared infrastructure-wide, not per-org, so it's a network-layer allowlist, not an identity boundary. There's no equivalent of "static NAT per org" for outbound Apex callouts today. 

     

    4. Yes — a relay/gateway in front of the private service is the standard, recommended pattern here, and I'd recommend it. Put a lightweight reverse proxy (or MuleSoft Anypoint, or even a small managed API gateway) in a publicly reachable spot the vendor controls, with the vendor's actual private-network service sitting behind it. Salesforce calls the gateway over the public internet (allowlist-friendly, small surface), and the gateway — sitting inside the vendor's trusted network — forwards to the private endpoint. This gets you real identity-based control (API key, mTLS, OAuth — now actually meaningful since the gateway is an app-layer listener) instead of a shared-IP-range network allowlist, and it decouples you from Salesforce's outbound range changes entirely, since your callout target becomes a stable endpoint the vendor owns. This is what most orgs land on for exactly this scenario — it's a small piece of infra to own, but it's the durable fix. 

     

    Reference:

    https://unofficialsf.com/understanding-private-connect/

0/9000

Hi Team,

I've completed the quests for this month, including the Agentforce Quests and Ranger Quests. 

 I just wanted to check — are there any forms I need to fill out either before or after completing the quests to ensure I'm eligible for Salesforce goodies?

I'm a huge fan of Salesforce goodies, and I would appreciate any guidance you can provide. 

 Thanks so much for your help!

3 risposte
  1. 29 apr 2025, 05:19

    Completing the quests does not translate into receipt of goodies. If a community badge is associated with these quests you will be able to view the same in your TH profile two weeks post closure of the quest. Goodie recipients are chosen by draw of lots since there will be hundreds or thousands who complete these quests.  

     

    Hope this clarifies. 

0/9000