Apply Clickjack Protection to Less Common Browsers
To help protect your users against clickjacking attacks, Salesforce applies the
Content-Security-Policy: frame-ancestors HTTP header directive to the pages that Salesforce serves
when that directive is supported. To extend clickjack protection to more users, include that
directive in the rare cases when Salesforce can’t identify whether the requesting app or
specialized browser supports the directive.
Required Editions
Available in: both Salesforce Classic and
Lightning Experience
Available in: Contact Manager, Group, Professional,
Enterprise, Performance, Unlimited, and Developer
Editions
User Permissions Needed
To modify session security settings:
Customize Application
The supported browsers and devices for Salesforce Lightning Experience and Salesforce Classic
support the required HTTP header directive for clickjacking protection. We recommend that you
enable this feature only if your users access Salesforce via unsupported apps or specialized
browsers with unclear support for Content-Security-Policy: frame-ancestors.
Warning When this option is enabled,
users who access Salesforce via an app or browser that doesn’t support the
Content-Security-Policy: frame-ancestors directive can experience errors if that lack of support
is unclear. We encourage you to test this feature in a sandbox via your users’ apps and
browsers. Then weigh the benefit of the additional clickjack protection against the errors that
users can experience.
From Setup, in the Quick Find box, enter Session Settings, and then
select Session Settings.
In the Content Security Policy (CSP) Directive Rendering section, select Apply
CSP directives for less common browsers, and then save your changes.
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.