Skip to main content
그룹

SecurityForce

Security is a team sport -- This is a collective of Salesforce and Security practitioners working on building a secure Salesforce ecosystem.

Hello, We recently ran a Health Check and one of the items in there was to turn on - Require HttpOnly attribute. I read a lot of documentation and other available blogs that state 99% of the time it should be good to enable it. Obviously we would do that in a full sandbox and test things out, but I wanted to ask folks here if there are any known issues or caveats we should be aware of and look for them first. We have a ton of managed packages in the organization.  

 

Thank you so much! 

답변 4개
  1. 4월 20일 오후 10:49

    The Developer Console is not available if the Require HttpOnly attribute is selected.  That is the main drawback.  Some VisualForce pages rely on Javascript getting the session token from the cookie and this will also fail. 

     

0/9000

Regarding Spring '26 "Authorized Email Domains" security enhancements., Salesforce indicates exceptions for gmail.com and outlook.com domains. My University runs our email on Outlook servers, but our domain name is that of the University. Does the exception by Salesforce apply to Outlook servers regardless of domain name, or only for outlook.com

as the domain? 

Thank you!

답변 1개
  1. 3월 30일 오후 5:28

    Great question regarding the Spring '26 Authorized Email Domains security enhancement. Here's the clarification:

    The exception is domain-specific, not server-based.

    Salesforce's exceptions for gmail.com and outlook.com apply to those specific domains, not to all mail servers that happen to use the underlying infrastructure. This means:

    1. If your university email is sent through servers hosted on Microsoft 365 (Exchange Online) but the sender domain is youruniversity.edu, that does NOT automatically qualify under the outlook.com

    exception. 

    2. The exception applies only when the sender's email address domain is literally

    outlook.com, hotmail.com, or other Microsoft consumer email domains — not institutional domains using Microsoft infrastructure.

    What this means for your University:

     

    Your university's email domain (e.g.,

    unc.edu) will need to be explicitly added to the Authorized Email Domains list in Salesforce Setup to avoid disruption after the Spring '26 enforcement date.

    Action required:

     

    1. Go to Setup [right arrow] Email [right arrow] Authorized Email Domains (or "Organization-Wide Email Addresses" depending on release). 

    2. Add your university's email domain(s) to the authorized list. 

    3. Review the full release notes at the link you referenced to confirm the exact enforcement date and any additional exceptions.

    If you're unsure whether your domain qualifies, contacting Salesforce Support to confirm is the safest approach.

0/9000

I am not sure if this is the group to ask or not, but I work for a Nonprofit and while reviewing the Login History for the past 6 months, I noticed that a user who has been inactive since 2016, appeared to try to log into their SF account.  The login failed as the user is inactive, however, my question is more around would this be an attempt of someone getting a hold of an old email, username, password, etc and using this to try and login to our SF instance?  I do know it was from a Mac, it was Chrome and the IP address is from Clevland (or appears to be) and we are in Cincinnati.  Anyway, I am trying to determine if I should be concerned or note. 

 

#Security #Nonprofit

답변 4개
  1. 2월 24일 오후 9:31

    Hi @Heath Parks

    , i hope you should not as If the user is inactive and the login shows “Failed – User is inactive”, then No access was granted ,No password was validated No data was exposed. 

     

    This is usually one of three things:

    • A bot trying old leaked credentials
    • Someone testing an old saved password
    • Random automated login attempt

    You’d only worry if you see: Multiple attempts , Attempts across several users and Successful logins 

     

    Hope that helps  

     

    Thank you

0/9000

https://invite.salesforce.com/eventmonitoringforsecurityintel?utm_campaign=uki_cbaw&utm

[…]t-1768993355&utm_medium=organic_social&utm_source=linkedin 

 

This 60-minute webinar will equip you with the knowledge to leverage Event Monitoring for superior security intelligence. Over 50 minutes, we will cover four critical areas: We begin with an Introduction to Event Monitoring, outlining the standard audit trail capabilities and clearly differentiating between active security monitoring and passive compliance logging. Next, we delve into Event Types & Data Model, examining crucial events like logins, API usage, and data exports, discussing the differences between real-time and historical event data, and breaking down the structure of the Event Log Files . The in-depth Implementation & Configuration section guides you through enabling Event Monitoring, setting up custom event log retention policies, and establishing seamless integration with your existing SIEM (Security Information and Event Management) platforms. We conclude by exploring practical Security Use Cases, demonstrating how to detect anomalous user behavior, build specific compliance reporting scenarios, and integrate event data into your incident response workflows.

0/9000
0/9000
0/9000

https://sforcemaximizer.com/how-to-secure-your-agents-data-at-dreamforce-2025-for-admins-and-architects/

 

If you're an admin, architect, or IT leader who's eager to secure your Agents and learn practical best practices at Dreamforce 2025, check out this wonderful blog by

@Rachel Beard showcasing her hands-on session at Dreamforce this year. It’s a fantastic resource to help you prevent risks and confidently address questions from your CISO and compliance teams. @Admin Tricks@Admin Group, Philadelphia, US@Admin Group, Mount Laurel, US@Admin Group, Columbia, MD, US@Admin Group, Raleigh, US@Marketer Group, Philadelphia, US@Architect Group, Atlanta, US@Architect Group, Atlanta, US@Architect Group, Chicago, US@Architect Group, Chennai, IN@Admin Addicts@SecurityForce@The Blog Group

0/9000

My company was planning to implement API Access Control. After enabling it we have ran into couple issues. Latest is that the "Is single sign-on enabled" permission has disappeared. We haven't used delegated SSO in a long time so it doesn't impact the SSO as such but we have kept is permission enabled for end user profiles to prevent password resets. Is there another way to prevent password resets for users based on profiles? For admins and some special cases we still want to have passwords so we can't disable password login on the org level. 

 

Why can't these impacts be documented? It is really frustrating to discover these on trial and error basis. Like that also SOAP connections are impacted and apparently those cannot be authorized but you'd need to give "Use any API client" permission for the concerned user.

답변 4개
  1. 2025년 9월 9일 오전 7:43

    You are right actually, it is not enabling of API Access Control that had made the "Is Single Sign-on Enabled" permission to disappear but disabling of the "Disable login with Salesforce credentials". Someone who shouldn't had done this without asking/informing and coincidentally at the same time as we were testing API Access Control.

0/9000

Consider the specific recommendations in this article to improve the security posture of your org in light of the ongoing social engineering threats: 

 

Protect Against the Salesforce Data Loader Related Security Threats

0/9000

Hello. Hope you are doing well. 

Every time I am trying to auth to 

https://security.my.salesforce-sites.com/sourcescanner/

 I got an issue on the image.  Incognito mode does not work as well.

I use PBO org credentials to auth and System Administrator user. PBO is DevHub

 

Does anybody know how to fix it?

0/9000