You are here:
Permission Assignment Expiration Considerations
When working with permission assignments that expire, keep these considerations in mind.
Required Editions
| Available in: both Salesforce Classic and Lightning Experience |
| Available in: Essentials, Contact Manager, Professional, Group, Enterprise, Performance, Unlimited, Developer, and Database.com Editions |
- When a permission assign expires, permissions assigned to users via non-expiring
permission sets, permission set groups, or through a profile still
apply.
Let’s say that you assign a user to a permission set group that includes create permissions on the Contracts object. The user’s assignment to the group expires in a week. The user also has create permissions on the Contracts object via a permission set that doesn’t expire. When the permission set group assignment expires in a week, the user still has create abilities on the Contracts object via the permission set.
- SOQL queries don’t return user assignment information for permission assignments
that expire. Assignments that expire are treated as soft-deletes. You can
retrieve the expiring assignment information using the
ALL ROWSclause. - When an assignment expires, the user remains assigned to the permission set or permission set group. However, the user can't access the permissions associated with the permission set or permission set group.
- If permissions included in a license are removed by Salesforce, assignments for permission sets or permission set groups that require this license are no longer valid. When this change occurs and the Permission Set & Permission Set Group Assignments with Expiration Dates setting is enabled, Salesforce marks the assignments as expired to help Salesforce admins track these changes and adjust permission sets and permission set groups as needed. If this setting isn't enabled, Salesforce removes assignments for the related permission sets and permission set groups.
Did this article solve your issue?
Let us know so we can improve!
