Loading
Prepare for Email to Become the Default Login ExperienceRead More
Set Up and Maintain Your Salesforce Organization
SessionHijackingEventStore Policies

SessionHijackingEventStore Policies

Session hijacking event policies monitor when unauthorized users gain ownership of a Salesforce user’s session with a stolen session identifier.

Required Editions

Available in both Salesforce Classic (not available in all orgs) and Lightning Experience.

Available in: Enterprise, Unlimited, and Developer Editions

Requires Salesforce Shield or Salesforce Event Monitoring add-on subscriptions.

Policy at a Glance

Object Conditions Available in Condition Builder Actions
SessionHijackingEventStore CurrentUserAgent, CurrentIp, CurrentPlatform, CurrentScreen, CurrentWindow, PreviousUserAgent, PreviousIp, PreviousPlatform, PreviousScreen, PreviousWindow, Score, SourceIp, UserId, Username Notifications

What You Can Do with It

Create a policy that can:

  • Generate an in-app notification when Salesforce detects a session hijacking attack on your org with a score greater than 10.
  • Send you an email when Salesforce detects a session hijacking attack from a specific IP address.

For more information on the SessionHijackingEventStore object, see SessionHijackingEventStore

 
Loading
Salesforce Help | Article