To enhance customer data protection, Salesforce has implemented new AI-driven anomaly detection for login activity. These changes focus on mitigating potentially malicious account takeovers. When Salesforce detects significant deviations in a user's login behavior, automated response actions are triggered to protect the account. Those responses can include revoking all access, requiring a password reset (if password authentication is used), and notifying the org's Salesforce admin.
This article answers the questions: what is Salesforce login anomaly detection and containment, when did it take effect, and what should you do if a user is frozen after a containment action? It explains the detection and notification process, the containment actions, and how to resolve a login containment event.
Salesforce applied this change in early April 2026. You may also have received notifications in early March 2026 when Salesforce enabled this change on a temporary basis.
The existing Login Anomaly feature included in Shield Threat Detection will continue to operate through at least June 30, 2026. In rare cases, customers may see duplicate detections between the two methods.
Salesforce monitors login behavior, specifically for network activity, client, authentication events, and geolocation tags. When Salesforce detects certain novel usage patterns in that behavior, including certain uses of anonymizing proxies, it notifies admins for affected instances of an anomaly detection and takes steps to contain the subject user. Salesforce also notifies admins (users with Modify All Data permissions) when it observes certain novel usage patterns in these behaviors in the absence of anonymizing proxies, which can also indicate suspicious login activity.
Salesforce triggers the following actions when it detects significantly abnormal patterns in login behavior:
If you receive an email about a containment action, review the activity detailed in the email and take these steps:
If the org's only Admin is locked out and you cannot restore the affected user account, contact Salesforce Support for assistance. If needed, you can find Salesforce Customer Support phone numbers through the Contact Salesforce Support link in Additional Resources.
005319571

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.