Loading
Prepare for Email to Become the Default Login ExperienceRead More
Multiple Salesforce Services Impacted - Support Case Creation Also AffectedRead More
Intermittent freezing when using using certain browser versionsRead More
Set Up and Maintain Your Salesforce Organization
Best Practices for Investigating Guest User Anomalies

Best Practices for Investigating Guest User Anomalies

Keep these tips in mind when you investigate unusual user behavior to ensure your data stays secure.

Required Editions

Available in both Salesforce Classic (not available in all orgs) and Lightning Experience.

Available in: Enterprise, Unlimited, and Developer Editions

Requires Salesforce Shield or Salesforce Event Monitoring add-on subscriptions.

We recommend that you review the following settings.

  • Organization Wide Default (OWD) Sharing Settings:
    • Guest user external org-wide defaults are set to private.
    • Guest users can’t have more than read access to data.
    • Guest users can only get access to records through guest user sharing rules, a special type of criteria-based sharing rule.
  • Guest User Profiles:
    • A suspicious event caused by guest user profiles likely means that guest users accessed objects via Apex and submitted SOQL queries that have returned results. Review any Create, Read, Update, Delete (CRUD) access owned by each standard or custom object within guest user profiles.

To generate a report showing your current Guest User access and permissions, use the Authenticated and Guest User Access Report and Monitoring app, which can be found in the AppExchange marketplace.

See these best practices to ensure that you are keeping your orgs with guest users secure: Manage Users and Data Access.

 
Loading
Salesforce Help | Article