Skip to content
TOPIC

Authentication.

POSTS
13
OLDEST
2026
NEWEST
2026

All posts.

SEP 17 2026

An Experience Cloud Tile Launch Is a Session Hand-Off, Not a Login

Moving between Experience Cloud sites reuses one session, so a Login Flow on the destination never fires. Here is how to prove it from the login records.

SalesforceExperience CloudAuthenticationArchitectureSecurity
SEP 15 2026

SAME_ORG_SSO: Why One Experience Cloud Site Cannot Be an Identity Provider for Another

Salesforce blocks OIDC between two Experience Cloud sites in one org. Why a site is not an identity authority, and why SAML is the one route still open.

SalesforceExperience CloudAuthenticationArchitectureSecurity
AUG 30 2026

Salesforce Restricts the OAuth Device Flow on 30 November 2026: Your Connected App Has to Become an External Client App

From 30 November 2026 the OAuth device flow works only from local external client apps. Connected apps that use it must migrate or stop authenticating.

SalesforceSecurityIntegrationAuthenticationConnected Apps
AUG 28 2026

Salesforce Retires the OAuth User-Agent Flows on 20 February 2027: Move to Web-Server Flow with PKCE

The OAuth user-agent and hybrid user-agent flows retire on 20 February 2027. What breaks, why a token in the URL is the problem, and where to move next.

SalesforceSecurityIntegrationAuthenticationConnected Apps
AUG 25 2026

Salesforce Winter '27 Requires Use Any API Auth for SOAP login(): Find Your Exposure First

Winter '27 requires the Use Any API Auth permission for SOAP API login(), or the call errors. The queries to size your exposure and check who holds it.

SalesforceSecuritysalesforce-adminIntegrationAuthentication
AUG 24 2026

Salesforce Certificate Trust Store: Your Own Root CAs, for Named Credentials Only

Winter '27 lets you upload and manage your own root certificates in Salesforce. The scope is narrower than it first looks, and that scope is the story.

SalesforceSecurityIntegrationAuthenticationCompliance
AUG 6 2026

Sending Email from Salesforce Securely: SMTP Is Not Encrypted by Default

SMTP is cleartext by design and TLS is opportunistic. Why Preferred Verify still sends in the clear, and what to configure so email is actually protected.

SalesforceSecuritysalesforce-adminComplianceAuthentication
JUL 16 2026

Locked Out After Salesforce MFA Enforcement: Recovery Paths, Temporary Codes, and the Break-Glass Account You Should Have Built

Locked out after Salesforce MFA enforcement? The recovery paths, temporary codes, Support realities, and how to build a break-glass admin account for your org.

SalesforceSecurityMFAAuthenticationsalesforce-adminIncident Response
JUL 7 2026

Salesforce MFA Enforcement Update: What Was Paused, What Still Applies, and the Revised 2026 Dates

Salesforce paused its all-employee MFA enforcement over a security-key enrolment bug and revised the 2026 dates. Here is what moved and what still applies.

SalesforceMFASecurityAuthenticationCompliancesalesforce-admin
JUL 2 2026

Salesforce Retires the OAuth Username-Password Flow on 20 February 2027: Migrate Before Your Integrations Break

Salesforce postponed the OAuth 2.0 username-password flow retirement to 20 February 2027. What breaks, how to find affected integrations, and how to migrate.

SalesforceSecurityOAuthIntegrationsalesforce-adminAuthentication
JUN 21 2026

Salesforce Summer '26: The SAML Retirement and Apex Secure-by-Default Changes That Break Orgs Quietly

Two Summer '26 changes break orgs without warning: retiring single-configuration SAML stops SSO logins, and Apex now defaults to with sharing. What to check, where.

SalesforceSecuritySSOApexsalesforce-adminAuthentication
JUN 19 2026

Salesforce Security Enforcement in 2026: Every Change, Date, and What Admins Must Do

Across 2026 Salesforce turns a stack of security recommendations into hard enforcement: MFA, report step-up auth, IP blocking and more. The full list and dates.

SalesforceSecurityMFAsalesforce-adminComplianceAuthentication
JUN 17 2026

Salesforce MFA Enforcement in 2026: What Admins Must Verify and Do

Salesforce moves from contractual MFA to hard enforcement in mid-2026, with a stricter phishing-resistant bar for admins. How to verify your org and comply.

SalesforceMFASecuritySSOAuthenticationCompliance