Winter ’27 enforces the Profile Filtering update. Once it is on, a user sees only their own profile name unless they hold View All Profiles, so any validation rule, formula field, flow, or Apex class that reads another user’s profile name is in scope. The fastest fix is to grant View All Profiles more widely, which restores the feature and widens visibility at the same time. The stronger fix is to find every reference, test as an end user, and replace profile checks with custom permissions.
Saman Attar breaks a working automation in a sandbox, shows what fails in Apex, a formula field, and a validation rule, and fixes each one. No prior Apex experience is assumed. The session also covers the OAuth 2.0 username-password flow retirement, now enforced February 20, 2027, and the migration path to client credentials.
Viewers will leave able to inventory profile name references, test them against Winter ’27 in a sandbox, and recognize when a fix restores a feature by loosening access.
Guest speaker Saman Attar, Senior Software Engineer at F5 and Founder of CampApex.org, joins Matt Meyers, CTA, CoFounder and CEO of EzProtect.
Profile Filtering removes one way a compromised user can learn which profiles exist in your org. Files and links arriving through Experience Cloud, Email-to-Case, and API integrations are another path in, and Salesforce’s own documentation says native scanning flags only files with a high probability of being malicious. EzProtect reads every file and every URL before it reaches a record. Book a demo and watch it catch what native scanning lets through.