Ceili Winter ’27 Release Notes
11.9.2026
Intro
Here is Ceili’s traditional summary of the upcoming new features and changes in Salesforce’s Winter ’27 release. Salesforce publishes an update three times a year, bundling both major and minor changes. On this page, we’ve pulled together a compact overview of the updates most likely to affect how your organization uses Salesforce.
Each feature gets its own short section below, along with the concrete benefits customers can expect and any action required, where applicable. We’re happy to help if you need support putting new features to use – just reach out at support@ceili.fi.
You can find the exact date Salesforce installs the Winter ’27 release in your own organization at status.salesforce.com (Maintenance tab). Enter your Salesforce instance number – found under your company information in Salesforce – to see it.
Content:
General updates in Salesforce
Move your connected apps over to External Client Apps
A built-in migration path lets you convert existing connected apps into External Client Apps (ECAs), a newer model that keeps developer-owned settings – protocol, OAuth flows, scopes – separate from the admin-owned policy layer: who’s allowed to use the app, IP relaxation, refresh-token lifetime, and so on. Your consumer key and secret carry over, so nothing breaks on the integration side.
- Why: Connected apps blend vendor capability and customer policy into a single record, which makes it hard to answer a simple governance question: who approved this, and under what rules? ECAs are closed by default and only opened deliberately, with a cleaner audit trail to match.
- Who: Any org using connected apps for integrations. Migration isn’t available if the app has user provisioning, a custom Apex handler, Canvas, dynamic client registration, or SAML with Triple DES encryption. Single sign-on connected apps can’t migrate at all, and ECAs don’t support the username-password flow.
- How: In Setup, go to App Manager, find the connected app, and select Migrate to External Client App if it’s eligible. Pull a list of OAuth usage across your connected apps first and cross-check it against login history so you know which integrations to tackle first. Remember that sandbox refreshes don’t carry ECAs over, so you’ll need to rebuild them there each time.
Inline-edit list views with fewer restrictions
Two new interface settings let users edit any field they have access to directly from a list view, not only the ones shown on the page layout – and inline editing now works even when a list view mixes several record types, which used to block it outright.
- How: In Setup, go to User Interface and turn on the two new inline-editing settings.
Retiring Salesforce features
SOAP API’s login() call is going away for versions 31.0–64.0
Salesforce is removing the login() call from SOAP API versions 31.0 through 64.0 (newer versions dropped it long ago). Any app or middleware that authenticates with a username, password, and security token through this call will stop working once the change lands – switch to OAuth 2.0 through a connected app or External Client App instead.
- When: Takes effect in the Summer ’27 release.
- How: Use Event Monitoring to spot orgs and integrations still calling SOAP login(), then move them to OAuth 2.0. Test the change in a sandbox first using the release update’s Enable Test Run option.
Get ready to lose Activity 360 reporting and Activity metrics
Four legacy Einstein Activity Capture reporting tools are on their way out: Activity 360 reports, the Activities analytics dashboard, Activity metrics, and Recommended Connections. In their place, email and event data will live in standard Task, EmailMessage, and Event records – opening that data up to standard reports, Flow, and Agentforce, something the old dedicated objects never allowed.
- When: Retirement is set for the Spring ’27 release, around February 2027.
- How: Rebuild Activity metrics as standard reports on Task and EmailMessage objects (or use Flow for anything you need in real time). Recreate the Activities dashboard with standard report types or Tableau and replace Recommended Connections with a custom invocable action.
Plan your move off Lightning Sync and onto Einstein Activity Capture
Lightning Sync – the tool that keeps contacts and calendar events in step between Salesforce and Exchange or Google – is being phased out. Salesforce points everyone still on it toward Einstein Activity Capture, which adds email sync and AI-driven capabilities on top, and provides a dedicated migration tool to get there.
- When: Lightning Sync retires in April 2027. Microsoft is shutting down Exchange Web Services on its own separate timeline in the same window – unregistered traffic gets blocked starting October 1, 2026, and EWS closes entirely on April 1, 2027 – so orgs syncing through Exchange are on a tighter clock.
- Who: Mainly orgs running Lightning Sync against Microsoft Exchange (EWS).
- How: Check whether you’re on EWS and, if so, move to Microsoft Graph authentication first. Review the migration tool’s prerequisites, run its readiness check, grant users Einstein Activity Capture permissions, then complete the switch – Lightning Sync keeps running until you do.
Switch Einstein Activity Capture’s Microsoft 365 connection to Graph
Any Einstein Activity Capture connection still authenticating to Microsoft 365 through the older Exchange Web Services protocol needs to move to Microsoft Graph. This isn’t Salesforce’s call – Microsoft is retiring EWS access for third-party apps on its own schedule, and EAC (along with Salesforce Inbox and Lightning Sync) relies on it to read mailboxes and calendars.
- When: Microsoft starts blocking unregistered EWS traffic on October 1, 2026, and shuts it down completely on April 1, 2027.
- Who: Your Microsoft 365 global admin needs to grant Graph consent at the tenant level, not per user, and confirm no conditional access policy is blocking the new app.
- How: Map out which connections and downstream reports or automations depend on EAC or Lightning Sync today. Request Graph admin consent from Microsoft 365 as early as possible, test the switch in a sandbox, pilot it with a small group, then roll it out fully and double-check your reports and automations afterward.
From Setup, in the Quick Find box, enter Einstein Activity Capture, and then select Settings.
In the Summary tab, click Upgrade to Microsoft Graph
View authentication-mapping details.
Consent to confirm that this upgrade requires each user to reconnect to their accounts to fully transition to Microsoft Graph.
Click Finish to complete the upgrade to Microsoft Graph
Salesforce Connect’s cross-org adapter drops its old login method
The password and OAuth 2.0 authentication options for the Salesforce Connect cross-org adapter are being retired, since both rely on the SOAP login() -call that’s also going away. Named credentials take over as the adapter’s authentication method – a sturdier, more secure option.
When: Legacy authentication for the cross-org adapter is retired in Spring ’27. Check Trust Status for your instance’s exact upgrade date.
How: Move any cross-org adapter external data sources over to named credentials before the cutoff. You can review the change under Release Updates in Setup.
Salesforce for Outlook shuts down in December 2027
Salesforce for Outlook – the older side-panel add-in that syncs contacts, events, and tasks – is being discontinued. It was built for Salesforce Classic and an old version of Internet Explorer, and once IE11 support ends, the add-in has nothing left to run on. Everything already synced stays in place in both Salesforce and Outlook; only the add-in itself, and the settings tied to it, go away.
- When: December 2027.
- How: Move to Outlook Integration for the side-panel experience, and to Einstein Activity Capture for contact and event syncing.
Sales Cloud (Agentforce Sales)
Catch escalated cases before they put a deal or account at risk
Your reps get a prioritized alert whenever an open, escalated case is tied to an important opportunity or a bookmarked account – keeping deals on track instead of letting a support issue quietly derail one. They can open the case straight from the feed, or post about it in Slack, without leaving Sales Workspace.
- Where: Lightning Experience, in Enterprise, Unlimited, and Agentforce 1 Sales editions with the Sales Foundation add-on.
- How: On the Sales Workspace page, check the All Signals section for escalated cases. To post one to Slack, click Post in Slack next to that signal.
See Sales Engagement data reflected in fresh reports
Sales Engagement data now lives natively on the Salesforce platform, which means it shows up in new and updated reports as well as the Sales Engagement Sample Dashboard – giving you a steadier, more consistent read on engagement and an easier way to drill into trends.
- Where: Sales Engagement in Lightning Experience, included in Performance, Einstein 1, and Unlimited editions, and available at extra cost in Professional and Enterprise editions.
- Why: Storing this data natively on the platform makes reporting more reliable and consistent, and gives you more room to filter and drill into individual engagements for trend analysis.
- How: Find the Sales Engagement reports in the Sample Sales Reports folder, or view the data through the Sales Engagement Sample Dashboard.
Get a sharper read on deal health with enhanced Opportunity Scoring
The enhanced Opportunity Scoring model, powered by Data 360 AI, gives your reps a clearer signal on which deals are healthy and which are at risk – factoring in actual conversation data and engagement signals alongside the standard opportunity fields, rather than relying on those fields alone.
- Where: Lightning Experience, in Performance and Unlimited editions with Sales Cloud. Enterprise Edition needs the Agentforce or Revenue Intelligence add-on for this one.
- How: From the gear menu, open Salesforce Go, search for Opportunity Score, and turn it on by following the setup steps.
Keep tabs on email address verification across every domain your users send from
A new page lists every email domain your active users send and reply from, along with how many addresses on each domain are verified versus not – a quick way to see where you stand.
- Where: Lightning Experience and Salesforce Classic, in every edition except Database.com.
- Why: Salesforce requires both user- and domain-level email verification – a valid DKIM key or a verified Authorized Email Domain for the sending domain, plus verification of any separate return address a user sets. Email only goes out from a user’s address once every requirement is met, so this list helps you spot which domains still need attention, and where a substitute address might make sense in the meantime.
- How: In Setup, search for User Email Domains and open it, then click List Domains to populate the table.
Get more precise about what Einstein Activity Capture skips
You can now use keywords to automatically catch and exclude emails containing specific words or phrases, and wildcard rules to exclude calendar events and messages tied to web domains. Sensitive-data detection has also gotten smarter: it now skips emails marked “confidential” as a subject prefix, and Outlook messages flagged confidential or private – previously, domain exclusions only worked on an exact match.
- Where: Lightning Experience, in Starter Suite, Pro Suite, Professional, Enterprise, Unlimited, Einstein 1 Sales, and Agentforce 1 Sales editions.
- How: In Setup, search for and open Einstein Activity Capture. Add keyword exclusions under Don’t Capture Sensitive Emails, then Manage and Add. Manage domain exclusions, including wildcard rules, under Excluded Addresses.
Add a Follow button to the Dynamic Highlights Panel
Admins can switch on a native Follow button inside the Dynamic Highlights Panel, so users can subscribe to a record – and get notified about field changes, posts, tasks, and comments – right from that panel, without hunting for the button elsewhere on the page.
- How: Edit the Dynamic Highlights Panel component’s properties and turn on the Follow button.
Keep manual shares intact when a record changes owner
A new sharing setting stops manually granted shares from disappearing when a record’s owner changes – previously, an ownership change could wipe out those shares, leaving users to redo them after the fact.
- Why: Protects against accidental loss of access around ownership changes, such as territory reassignments or team turnover.
- Who: Off by default; once turned on, it applies org-wide to every record.
- How: In Setup, go to Sharing Settings and enable the option that keeps manual shares in place when ownership changes.
Service Cloud (Agentforce Service)
See a case’s original attachments without leaving the case
Whatever the customer attached when they logged the case now appears as thumbnail icons right under the Case Description field, so support reps don’t have to scroll down to the Files related list just to check what came in with the case. Up to three attachments show inline; beyond that, a popup lists five at a time with a link through to the full Files list.
- Why: One less click for a rep picking up a fresh case – the original evidence, a screenshot, a log file, a document, is visible the moment the case opens.
- How: In Setup, go to Support Settings and turn on Show Original Case Attachments.
Analytics
Preview a record from a Lightning report without losing your place (Beta)
A preview icon next to each row in a report opens the record’s key details in a side panel, so you can check a record without leaving the report or opening a new tab.
Embed Lightning dashboards on Lightning Web Runtime sites (Beta)
Drop a Lightning Dashboard component onto an LWR page and point it at a dashboard ID, and the dashboard renders right there on your Experience Cloud site – an option that used to be limited to Aura-based sites.
- How: In Experience Builder, add the Lightning Dashboard component to an LWR page and enter the dashboard’s ID.
In Experience Builder, drag the Lightning Dashboard component from the Components section to an LWR page. Enter the dashboard ID.
Embed Lightning reports on Lightning Web Runtime sites (Beta)
The same extension now covers reports: drag a Lightning Report component onto an LWR page and supply the report ID to have it display directly on the site – previously an Aura-only option.
- How: Add the Lightning Report component to an LWR page and enter the report’s ID.
Line up Data 360 -objects side by side with joined reports
Pull data from several Data Model Objects into a single joined report instead of exporting everything to a spreadsheet to compare it. Build separate blocks, each based on a report type tied to a different DMO, then group them by a field they share to line the results up side by side – an Accounts block next to an Opportunities block, both grouped by industry, for instance, quickly shows you which sectors have plenty of open opportunities but few accounts to show for it.
- Where: Data 360, in Developer, Enterprise, Performance, and Unlimited editions.
- How: Create or open a Data 360 report built on a data model object, switch the report format to Joined in edit mode, and use Add Block to bring in a second report type that shares fields with the first.
A recycle bin now catches deleted CRM Analytics work (Generally Available)
Deleted dashboards and lenses land in a dedicated recycle bin instead of disappearing for good. You can review what’s in there, restore an item to exactly the state it was in, and any subscriptions or notifications tied to it pause automatically for as long as it sits in the bin.
- Where: CRM Analytics in Lightning Experience. CRM Analytics itself is included in Developer Edition and available at extra cost in Enterprise, Performance, and Unlimited editions.
- How: To send a dashboard or lens to the recycle bin, open its action menu in edit mode and choose Move to Recycle Bin. Manage deleted items from the Home page – you have 30 days to restore one before it’s gone permanently.
Agentforce
Build Scheduler Agents in the new Agentforce Builder
Agentforce for Scheduler already let customers book, move, cancel, or check an appointment through plain conversation instead of a booking form – built from a ready-made Scheduling template that bundles an Appointment Management subagent and a confirmation step to verify who the customer is before touching any booking data. What’s new for Winter ’27 is that this template is now available in the newer Agentforce Builder, not just the original one.
- Where: Salesforce Scheduler on the Salesforce platform; Enterprise and Unlimited editions with Agentforce.
- Who: Requires Lightning Experience; external customers additionally need guest user support enabled.
- How: Clone the Einstein Agent User profile into a dedicated Agentforce user, grant it access to your scheduling data, build the agent from the Scheduling template, and set the customer-identification subagent’s scope to require confirmation. Test thoroughly before rolling it out.
New and updated standard actions and subagents for your agents
A batch of new and revised standard actions and subagents gives you a faster way to add capability to an agent, though what’s available depends on your edition and license. September 2026 brought a new Approval agent that helps reps and approvers work approval processes – submitting and recalling approval requests, tracking what’s still open, and generating AI summaries to speed up decisions. In the same update, the beta-stage Experience Builder Agent and its subagents were retired.
- How: Pull the new Approval Management, Search Approval Records, and Summarize Multiple Approval Items subagents straight from the agent library.
Marketing Cloud Next (Agentforce Marketing)
Get campaign-ready content faster with the Content Agent
Describe what a campaign needs to achieve in natural language, and the Content Agent drafts on-brand copy for email and SMS, drawing on your brand guidelines, campaign brief, and any media already sitting in Salesforce or in files you upload. It works with AI-generated images as well as your own, and you can tweak the draft inline before it goes live in Salesforce CMS.
- Who: Treat it as a head start on the first draft, not a substitute for a human check on tone, accuracy, and brand fit before anything ships.
Wire up automatic follow-through with Marketing Completion Actions
Attach a ready-made follow-up action to a campaign activity – notify a user, fire off an autoreply, route a lead to a person or queue – without building a separate flow for each case. Pick the action straight from Flow Builder.
See a campaign’s content and results in one place
The refreshed Campaign Overview surfaces a campaign’s key numbers alongside the status of everything tied to it – what’s ready, what’s live, how it’s doing – so you’re no longer bouncing between separate workspaces to check content readiness and performance.
Launch a custom flow template right from the campaign
Turn on a custom flow template directly from the campaign record and the system builds the flow and links it to that campaign for you – a step that used to mean creating the flow separately and connecting it by hand.
Clear out content and folders in bulk
Select several folders and published assets at once and delete them together, rather than working through them one by one – a quicker way to clean out anything outdated or no longer in use.
Keep agents and teams on brand with Brand Center
Brand Center brings your organization’s brand identity – voice, tone, visual style – into one shared place that the Content Agent and other AI agents draw on automatically when producing content, while people work from that same reference. The result is content that stays consistent whether an agent or a person made it.
Build personalization once, reuse it across every channel
Personalization logic – your data sources, inputs, and expressions – no longer has to be rebuilt for each channel. Set it up once and reuse it in SMS, WhatsApp, RCS, push, and in-app messages as well as email. A unified Data Sources tab brings inputs, data, and expressions together in one place, and you can write AMPscript or Handlebars expressions directly in any channel’s editor.
Measure how individual content blocks perform with Impression Region Tracking
Mark off a specific section of a message – in the content editor or through a Handlebars or AMPscript expression – and track that section’s own impressions, clicks, and click-through rate, across email, SMS, RCS, WhatsApp, and in-app messages. Custom reports can then break results down by region instead of only showing a single number for the whole message.
Localize an email without duplicating it for every language
Manage several translated versions of an email’s body copy, subject line, and preview text directly inside Email Builder, instead of cloning the whole email per language. The Content Agent can produce a first-pass translation for each language, which a marketer then reviews and polishes.
Troubleshoot email deliverability with step-by-step guidance
A 0-100 Email Deliverability Health Score rolls your whole sending program’s health into one number and flags you automatically once a metric slips into warning or critical territory. The dashboard behind it also digs into likely root causes and lays out numbered, priority-ranked fixes for the campaigns affected – no support ticket required.
Give recipients a webpage version of the email
Each recipient gets their own secure link, generated for them at send time on your organization’s branded domain, that opens the email as a webpage in a browser – a fallback for whenever the message doesn’t render properly in their email client.
Build landing pages and forms with custom HTML
When the standard component library can’t get you the look you’re after, marketers and developers can now write custom HTML for landing pages and forms instead. An automatic security scan checks that custom code before it goes live.
Connect forms and landing pages to more of your data
Forms can now read from and write to a wider range of sources – CRM objects, marketing objects, lead data – and landing pages can pull from those same sources as well as data graphs. The same update brings AMPscript and Handlebars support to landing pages, so you can personalize content and add conditional logic there without building a custom Lightning Web Component.
Build and clone marketing lists without leaving your workflow
Pull up a marketing list straight from the campaign record or from the Actionable List object’s home page, and clone an existing list along with its members – all without stepping out of whatever you’re already working on.
Get finer control over preference-page design and subscription content
Build a distinct preference page per channel, each with its own branding, its own visible subscription choices, and its own button styling. The same page can be surfaced from either a message’s content or its consent section.
- Where: Marketing Cloud Next, Growth and Advanced editions.
Send emails straight to an account or lead list, no segment required
Send a sales, transactional, or relationship email directly off a Salesforce account or lead list without first having to build a Data 360 segment – cutting out segment-processing time for sends that are quick or time-sensitive.
- Where: Marketing Cloud Next, Growth and Advanced editions.
Let record-triggered flows update consent automatically
The Consent Request flow action now works inside record-triggered flows too, so a consent change can fire the instant a related record changes – updating a contact’s subscription preference automatically when a related opportunity closes, for example.
See B2B marketing’s impact with ready-made dashboards
Tableau Next-powered dashboards pull account, opportunity, campaign, engagement, and attribution data together in one place, so you can see how marketing is performing against customer outcomes, campaign ROI, and attribution without building the reports yourself.
- How: Turn it on from the Marketing Cloud Assistant Home view in Setup.
Do more with RCS messaging in Marketing Cloud Next
RCS messages pick up swipeable, multi-card carousels (up to 10 cards, each with its own image and action), new action buttons, business-unit-level control over preference pages, and real-time flow analytics. Country coverage also expands, adding Austria, Canada, Spain, Sweden, and Poland among others.
- Where: Marketing Cloud Next, Growth and Advanced editions.
Trigger flows from order events in seconds, not minutes, over REST API
Order Return, Order Shipment, and Order Status Change events can now kick off a flow through the REST API in around three seconds, down from the 7-10 minutes it used to take. A new out-of-the-box schema also handles hierarchical order data with nested line items.
- Where: Marketing Cloud Flow Builder, Growth and Advanced editions.
Clone an audience flow without disturbing the campaign it’s still running
Cloning a flow used to leave the copy pointing back at the original’s resources, so an edit to the clone could quietly affect a campaign that was still live. Now, when you use Save as New Flow, you choose whether message content copies over as fully independent or stays linked to the original – segments, on the other hand, always clone as independent copies.
- How: Use Save as New Flow and pick which parts to duplicate outright and which to keep linked.
Account Engagement (Pardot) picks up a next round of capabilities
Account Engagement customers get a set of Marketing Cloud Next and Agentforce features: building a whole campaign from a single prompt, assembling an audience in plain language powered by Data Cloud, sending SMS as part of a multi-channel journey without a third-party platform, personalizing with merge fields that reach across objects (purchased products, webinar attendance, and the like), and rule-based dynamic content that adapts an email based on Data Cloud attributes.
- Where: Account Engagement Growth, Plus, Advanced, and Premium tiers, in supported regions.
- Who: Requires Sales Cloud or Service Cloud Enterprise Edition or higher, plus Data Cloud and the Account Engagement: Data Cloud Connector. Some of these features run on consumption-based pricing.
- How: Turn on Salesforce Foundations and Data Cloud Everywhere, set up the permission set licenses you need, and pick up consumption credits for any feature that requires them.
Set up Marketing Cloud Next from one place in Salesforce Go
Salesforce Go becomes the single starting point for getting Marketing Cloud Next running: installing the app, activating data streams, checking prerequisites, and configuring Identity Resolution – all from one place, filterable by category (channels, Einstein, optimization, analytics).
Add fields and one-off records to marketing objects without a CSV
Add new fields directly to a blank or existing marketing object from Data Explorer, and enter individual records by hand instead of importing a CSV – useful for a quick fix, test data, or a single record. The same release also brings direct support for marketing objects to the standard Flow elements (Get, Create, Update, Delete Records).
Web tracking and cookie-banner settings move to one place
Web tracking configuration and consent banner settings both move into Salesforce Go as a single, centralized area. Marketers can build custom consent banners for marketing landing pages and external sites from the same screen where tracking itself is set up.
Data Cloud (Data 360)
Build a segment by describing it
Describe the audience you want in plain language, and Data 360 works out the segment logic on its own instead of you manually picking objects, attributes, and filter operators. That opens up segment-building to people who don’t have a deep grasp of the underlying data model.
- Where: Data 360 segmentation; also available to Marketing Cloud Account Engagement (Pardot) customers through Data Cloud.
Reuse segmentation shortcuts when setting up an activation
The same attribute shortcuts your team already uses in segmentation now carry over into activation: on the activation canvas, marketers can pick a pre-defined attribute instead of navigating a complex data model path, and the same curated shortcuts serve both attribute and filter steps – which keeps attribute definitions consistent across the org.
- Where: Data 360, in Enterprise, Performance, Unlimited, and Developer editions.
- When: Available starting September 2026.
- How: Create the attribute shortcuts in Data 360’s segment builder. When you build or edit an activation, select those shortcuts from the activation canvas to add attributes or filters.
Customization (Flow, Apex)
More headroom for large data volumes with higher Apex heap limits
Apex’s heap-size ceiling goes up across the board: synchronous transactions (triggers, anything running in real time) move from 6MB to 10MB, and asynchronous ones (batch Apex, Queueable, Future methods) from 12MB to 25MB. Expect fewer “heap size too large” -errors in data-heavy integrations and batch jobs, and less need for workarounds that only existed because of the old ceiling.
- Why: Bigger batches and fewer forced batch-size cuts add up to fewer total batch runs when you’re pushing large volumes of data through.
Fewer Flow failures from record-locking conflicts
Flow now retries automatically when it runs into a row-locking conflict: hitting an UNABLE_TO_LOCK_ROW error pauses the flow briefly and retries the operation, giving whatever else is holding the lock time to release it, rather than the flow simply failing.
- Why: Cuts down on the manual error-handling workarounds admins have had to build just to cope with row-locking conflicts in busy orgs.
Organize flows with tags instead of naming conventions
Tag your flows instead of relying on naming conventions or juggling several list views to keep track of them. Set up tag categories, then attach one or more tags to a flow either right in Flow Builder when you save it or later from the Tags tab in the Automation app. From there you can filter, sort, and search flows by tag – a real time-saver once your flow library runs into the hundreds.
- How: Create Flow Tag categories, add tags under them, attach tags to a flow at save time or through the Automation app, and add a Tag column to a list view to filter and sort by it.
Update Apex and Flow for a change in how sharing recalculates
Part of sharing recalculation now happens asynchronously instead of synchronously, which changes the timing assumptions behind any Apex code or Flow built to expect an immediate result.
- Why: Code or a flow that checks record access right after an ownership or group change may now see a different outcome, since the recalculation no longer necessarily finishes right away.
- Who: Admins and developers whose Apex or Flow logic depends on sharing recalculation completing synchronously.
- How: Review any Apex code and flows that assume sharing recalculation finishes synchronously, and update them to tolerate an asynchronous result before this takes effect.
Web Console hides the Developer Console
Web Console is a modern, lightweight, browser-based IDE built directly into Salesforce. It is designed to be a seamless replacement for legacy tools and provides a unified development workspace, powered by VS Code for Web, without local installations or complex deployment.
Availability of Developer Console
The Developer Console option is no longer visible by default in Setup. To enable it, go to Setup, type Development in the Quick Find field and select Web Console. Switch the Enable Developer Console setting to Active. If Web Console is set to Inactive, Developer Console activates by default to restore the standard setup buttons. If both environments are set to Active, both options remain available from the Setup menu. See more details under Enable Web Console.
Key features:
- Modernizing legacy tools: Replaces outdated environments, such as Developer Console, and officially unsupported tools, such as Workbench, with a fast and modern interface.
- Running Apex and SOQL within the org: Write, test and edit Apex code or run Salesforce Object Query Language (SOQL) queries natively directly in your org.
- IDE without installation: Built on top of VS Code for Web, allowing both pro-code and citizen developers to edit code anywhere directly from the browser.
- Universal availability: Fully available and free in all supported versions and environments – offering an easily accessible alternative to paid tools, such as Agentforce Vibes IDE.
- Cost efficiency: Gives teams the ability to make quick direct changes without dependency on external local tools or heavy custom models.
Security, Identity, and Privacy
SOAP’s login() -call now needs the Use Any API Auth permission
Starting in Winter ’27, anyone authenticating through the SOAP API’s login() call needs the Use Any API Auth permission set — without it, authentication simply fails and the user gets an error.
- Who: Any integration, backup tool, or older piece of middleware that authenticates via SOAP login() with a username, password, and security token.
- Why: Integration users set up with only the bare minimum permissions are exactly the ones likely to be missing this one, and the failure happens server-to-server with no warning in the UI — a nightly data job can simply stop showing up with no obvious explanation.
- How: Check your login history over roughly the last 90 days to find integrations still using SOAP login(). Create a dedicated permission set granting Use Any API Auth and assign it only to the integration users you’ve identified.
Bring Authorized Email Domains along into a refreshed sandbox
Salesforce is retiring the old support-ticket exception that let you skip the verification link when a user changes their email. Its replacement, Authorized Email Domains, has your org prove it owns a domain via a DKIM key or a DNS TXT record, then lets you mark that domain to skip the usual 72-hour verification-link requirement on an email change. Because those domain markings and DKIM keys don’t survive a sandbox refresh, a one-click import now copies your authorized domains from production into the sandbox right after it refreshes.
- Why: Without it, every sandbox refresh quietly wipes your authorized-domain setup, breaking mass updates and testing until someone notices and rebuilds it.
- When: Available starting in Winter ’27; the underlying removal of the old exception takes effect December 1, 2026.
- How: Mark your production-authorized domains as sandbox-eligible, then run the one-click import right after each sandbox refresh. Domain verification itself happens via a DKIM key (Setup > DKIM Keys) or a TXT record (Setup > Authorized Email Domains), after which you still need to switch on the verification bypass separately for each domain.
Spot the fields guest users shouldn’t see
A new warning icon in the Guest User Sharing Rule Access Report flags fields that could expose personal data – on the Account object, for instance, it marks fields carrying revenue figures or address and contact details. From there you can go field by field and decide whether to adjust its sharing rule to keep that field, and its data, away from unauthenticated users.
- Where: Aura and LWR sites in Lightning Experience and Salesforce Classic, in Enterprise, Performance, Unlimited, and Developer editions.
- How: In Setup, search for Guest User and open the Guest User Sharing Rule Access Report. Pick a site and work through the flagged fields for each object.
Hide personal-information fields from guest users (Release Update)
Set field visibility for guest users independently of your other external users’ settings. Turning on Independent Guest Field Masking lets you hide specific fields from guest users alone, using a new Guest_PersonalInfo_EPIM field set – so you can lock down more personal data for guests without touching what portal users see.
- Where: Aura, LWR, and Visualforce sites in Lightning Experience and Salesforce Classic, in Enterprise, Performance, Unlimited, and Developer editions.
- When: Salesforce makes this update mandatory in Spring ’27.
- Why: Guest users typically need access to far fewer user fields than authenticated portal users do. A separate field set lets you conceal more personal data from guests specifically, while leaving the portal experience untouched.
- How: In Setup, search for Release Updates and open Conceal Personal Information Fields from Guest Users. Follow its testing and activation steps.
Manage passkeys and security keys without hassle
Your personal settings now include a dedicated Passkeys page listing every passkey and security key you’ve registered, where you can add new ones and retire ones you no longer use – previously, a new passkey could only be added during login itself. Registering more than one, say a laptop and a phone, gives you a fallback if your usual device isn’t handy.
- How: An admin enables built-in authenticators and physical security keys from Setup (Identity > Identity Verification), and can optionally allow passwordless login via passkey. From there, users manage their own passkeys under Settings > Passkeys > Add Passkey.
A roundup of what’s new for MFA and email security
Because security requirements keep shifting, Salesforce ships a steady stream of features to help you keep pace, and this article rounds up the recent additions supporting multi-factor authentication and email domain verification — including the passkey management described above, usability improvements to the MFA registration pages, and the email domain verification and Authorized Email Domains sandbox import covered earlier. Some of what’s listed here actually shipped back in Summer ’26, but Salesforce has gathered it into this Winter ’27 summary.
- Where: Lightning Experience, Salesforce Classic, and every version of the Salesforce mobile app.
Meet phishing-resistant MFA requirements with Login for Admin on mobile
A new Login for Admin option in the Salesforce mobile app gives admins an easy way to satisfy the newer security requirements, using browser-based authentication that resists phishing. Logging in as an admin, you can authenticate with a passkey – the fastest, most secure route into your org: enter your username and the app prompts you to confirm your identity with a passkey or password.
- Where: The Salesforce mobile app for iOS and Android.
- When: Available starting June 29, 2026.
- Who: Any Salesforce mobile app user can use this option, but it’s built especially for admins who need phishing-resistant MFA. If your org already runs Advanced Authentication (Native Browser) against your My Domain login server, you don’t need it.
- How: Tap the settings icon on the login screen and choose Login for Admin. The app walks you through secure authentication, including registering or using a passkey if your org has them turned on.