Salesforce Security Office Hours with Saman Attar

Loading Events

Winter ’27 enforcement begins in September 2026, and two of its changes reach into custom code that admins are often asked to approve without being able to read it. Profile Filtering limits users to seeing their own profile name unless they hold the View All Profiles permission, so anything that reads another user’s profile name stops working for the people who lack it. Those references appear in validation rules and flows, and they appear in Apex. The real security question is what happens next?

Granting View All Profiles more widely restores the broken feature immediately and widens profile visibility across the org at the same time, which makes the faster remediation the weaker one. The retirement of the OAuth 2.0 username-password flow raises the same question, because Salesforce is removing that flow for the specific reason that it passes user credentials directly in HTTP requests, and every connected app integration still using it will break.

This session gives admins and consultants enough Apex reading ability to open a class, follow what a query is asking for, how to check your Flows, and Validation Rules as well. and judge whether it is exposed to either change. Demo will only be for how to do an Apex profile check and will not demo anything for the OAuth 2.0 retirement.

No prior Apex experience is assumed. Attendees will leave able to assess their own org’s code against the Winter ’27 changes, where to go in Setup to enable settings ahead of the next release in your Sandbox, and to recognize when a proposed fix restores a feature by loosening access.

Guest speaker Saman Attar, Senior Software Engineer at F5 and Founder of CampApex.org, joins Matt Meyers, CTA, CoFounder and CEO of EzProtect.

Register for this event and we will see you online. 

Details

  • Date: September 3
  • Time:
    9:00 am - 10:00 am PDT
  • Event Category:
Go to Top