Skip to main content

#Salesforce Shield1 discussing

I've had multiple issues with the Security Center Insights job and have put in a few support cases. The first one fixed an issue and then other issues occurred so I put in another case.  Of course, all Salesforce did was put in another known issue (which is what they did the first time). Please upvote here if you're having similar issues! The Insights Job hasn't worked as expected since last October/November for me. Here's the Known Issue:  https://help.salesforce.com/s/issue?id=a02Ka00000mGsSu&isReported=Yes

 

#Security Center  #Salesforce Shield

0/9000

I have a SBX provisioned specifically for Shield (includes encryption, event monitoring, privacy center, and field audit trail) and I cannot find anywhere in Setup to enable Field Audit Trail.  I'm also confused about where to configure the retention policies.  I have read through the Security Implementation Guide and the FAT Implementation guide but I have not found any step-by-step instructions.

 

#Security #Salesforce Shield

8 answers
  1. Feb 1, 2024, 2:28 PM

    The Field Audit Trail Implementation Guide is probably your best resource.

    Once purchased, the FieldHistoryArchive big object is created automatically, with the archive period set to 18 months by default (this is when records are moved from the _History tables to the FieldHistoryArchive), and records are retained in the FieldHistoryArchive indefinitely (that is, until you manually delete them).

     

    IMO, Field Audit Trail still needs a lot of work.  There's no UI to configure it, you have to retrieve/deploy metadata files.  This is where some vendor products like RevCult have solutions to make things easier, but it's a gap that Salesforce should address.  Searching and retrieving records from big objects is also quite challenging due to the limitations and constraints imposed on big objects.

    Basically, Field Audit Trail provides just enough functionality to allow you to check a box for compliance reasons, but considerable work and additional tools are probably needed in order to make the data more consumable.

0/9000

Hi All,

1 ) Curious and wanted to confirm if you can reference a field value on transaction security? (checkbox = true)

 

2) I created an alert on personal information to prevent exporting of data like social .

I want to confirm if the condition NAME OF COLUMNS actually picks up the API name or Field Name OR label?

 

#Salesforce Shield #Shield Event Monitoring

1 answer
  1. Oct 2, 2023, 2:53 AM

    Hi David, this is not as simple as you would like.  It needs to use Apex, and not point and click policies.  The Column Headers in reports are a mixture of API name and aliases.  If you create a custom report type, it will work perfectly, however with standard report types, there are issues with columns with incorrect values.

    Turn on storage for ReportEvent and then do an account/contact report.  Add some fields and then do a query of the ReportEvent object using WorkBench.  You will see that it is not as you expect...  

    I raised a case last year, winter has a "fix" being released (https://help.salesforce.com/s/articleView?id=release-notes.rn_security_em_reportevent_columnheader.htm&release=246&type=5) however they did not fix all of the aliases.  For example, Phone2 is still a field on contact...  If you would like to join onto my case, please reference it 45306620.

0/9000
6 answers
0/9000

Hi All!

 

I am having an issue with Salesforce Shield, and its limitation with not being able to encrypt standard fields if Portal is enabled. In my project-scratch-def file (attached), I have no reference of Portals or Communities. They are also not enabled in my production instance. When I try to enable Probabilistic or Deterministic encryption for a standard field on the 'Encrypt Standard Fields' page I get the following error on save 'Platform Encryption cannot be enabled for standard fields when Portals are enabled. Client, Client Name'. When I search for 'Customer Portal Settings', in lightning i do not have this option, in classic i can see this option. I can see there is one portal (only in classic) enabled called 'Customer Portal', when i try to edit this i get the following error: 'The data you were trying to access could not be found. It may be due to another user deleting the data or a system error. If you know the data is not deleted but cannot access it, please look at our support page.'

 

Summary:

- This issue does not occur in production i can encrypt standard fields fine

- My project-scratch-def file does not contain any mention of Portal or communities as a feature

- I can only see the 'Customer Portal Settings' in classic, and trying to delete the portal gives an error.

 

Your help is much appreciated!

 

Many Thanks,

Shah

3 comments
  1. Nov 8, 2021, 4:54 PM

    Hello i am currently facing the same issue and i cannot find a way to disable the customer portal manually in the setup or using the sfdx cli. Did you find something that could help resolve that issue?

0/9000

Hello everyone, everything good?

In the company that I work we have an external community where some customers can upload files.

I would like to know if with Salesforce Shield it is possible to scan this uploaded file to check if it does not have any Virus or Malicious file?

 

#Salesforce Shield  #Shield Product  #Shield/Platform Encryption  #Shield Encryption  #Shield Platform Encryption Implementation Guide  #Shield Trail  #Security Shield  #Security  #Data Security  #Security Specialist

Thanks a lot for the help.
2 answers
  1. Aug 24, 2021, 12:18 PM

    Hi Leandro,

     

    Salesforce at the moment doesn’t provide a way to scan attachments, document uploads, or chatter for viruses or malicious content. But there is an open idea in Idea exchange that you can upvote. 

     

    https://trailblazer.salesforce.com/ideaView?id=08730000000IoG6

     

    Currently, there are few solutions available in Appexchange;

    1. https://appexchange.salesforce.com/appxListingDetail?listingId=a0N3A00000EFntJUAT

    2. https://appexchange.salesforce.com/appxListingDetail?listingId=a0N3A00000DqDF1UAN

     

    I hope it helps. 

     

    Regards,

0/9000

Is there an API call to check if streaming is enabled for a Real Time Event Monitoring Event (Setup > Platform Tools > Event Manager > Event)?

 

So as part of the Salesforce Shield release there is a new Salesforce Settings page at "Platform Tools" > "Events" > "Event Manager".

 

https://i.stack.imgur.com/Xe9VY.png

 

As seen in the image above, the Settings page contains a Grid listing various Real Time Event Monitoring Events. Each "Event" has a "Streaming Data" option. Is there way for me to programmatically check if "Streaming Data" is enabled for a specific "Event"?

 

Thanks.

4 comments
0/9000

🎉NEW on Einstein Analytics Plus Learning Days Webinars this week !!

 

Thursday October 1 at 9:00 AM PST (Pacific Time) (https://everytimezone.com/?t=5f751c00,3c0 )

 

Title: Encryption at Rest within Einstein Analytics

 

Speaker: Jason Huffman ( Senior Director, Analytics Cloud )

Description:

Join us to learn more about how you can take advantage of encryption at rest within Einstein Analytics. Salesforce Shield is required, but once you have enabled Shield then you may also apply encryption at rest within EA. We will talk about encryption in general within EA and focus on what happens when encryption at rest is enabled and the quick steps to enable it.

 

-- Register Now: https://attendee.gotowebinar.com/register/8973987816330414351

 

Unable to make the event? Or interested in past events? Recordings are posted here with all Einstein Analytics Learning Days: https://sfdc.co/ace-learning-days

 

Have a topic request? Please let us know!

0/9000

Day 1 of Camp Success Security is now complete! 

 

Please find attached the deck from the PM session of Day 1 on: Security Deep Dive

Building on Org Security Fundamentals, Salesforce Experts will go over how to uplift your existing security. We will demonstrate how Salesforce Shield and Data Mask can complement a holistic security strategy, and help satisfy security compliance requirements. 

 

Here is the video recording from both the AM & PM sessions: https://salesforce.vidyard.com/watch/Kzi813RWajFeGJM31XKYCs

 

(See post below for the AM deck) 

 

We look forward to seeing you again tomorrow for our deep-dive into Multi-Factor Authentication! 

6 comments
0/9000

📣EMEA: CAMP SUCCESS SECURITY - July 1-2 📣

 

🔒🔒🔒 Multi-factor Authentication 🔒🔒🔒

 

When: July 1st & 2nd, starting at 10:30am each day

 

Day 1 AM: Org Security Fundamentals 

Join Salesforce security experts to learn how Salesforce has built our products to be secure out of the box, as well as simple controls you can implement that will instantly increase the security of your org. In this session, we’ll discuss security as a defense-in-depth strategy, and how out-of-the-box features like setting up IP login ranges can help make securing your data easier. We’ll show you how to quickly understand the security health of multiple orgs at a glance. 

 

Day 1 PM: Security Deep Dive

Building on Org Security Fundamentals, Salesforce Experts will go over how to uplift your existing security. We will demonstrate how Salesforce Shield and Data Mask can complement a holistic security strategy, and help satisfy security compliance requirements. 

 

Register for Day 1. https://bit.ly/CampSuccessSecurity1

 

Day 2 AM: Secure Salesforce Account Access with MFA

We’ll hone in on one of the most important aspects of Salesforce Security: securing user accounts with multi-factor authentication (MFA).We know that keeping your Salesforce data safe and providing a way for users to log in quickly and easily are both top priorities. As security threats grow more common, it’s increasingly important to implement stronger measures to protect your data and customers. That’s why we recommend setting up MFA for all users logging in to Salesforce products. In the demo portion of this presentation, you will learn how to set up MFA in a Salesforce Org, and how to quickly pair a second factor with your Salesforce account.

 

Register for Day 2: https://bit.ly/CampSuccessSecurity2

 

Who is it relevant for?

Products: Sales Cloud, Service Cloud, Lightning Platform

Success Plans: Standard and Premier

Personas: CIOs, CISO, Admins, Executive Sponsors

 

Full agenda (see attached image) 

 

Hope to 'see' you there! 

8 comments
0/9000