Loading

Salesforce Login Anomaly Detection: Why Users Are Frozen and How to Resolve Containment Events

Publiseringsdato: Oct 9, 2026
Beskrivelse

To enhance customer data protection, Salesforce has implemented new AI-driven anomaly detection for login activity. These changes focus on mitigating potentially malicious account takeovers. When Salesforce detects significant deviations in a user's login behavior, automated response actions are triggered to protect the account. Those responses can include revoking all access, requiring a password reset (if password authentication is used), and notifying the org's Salesforce admin.

Løsning

This article answers the questions: what is Salesforce login anomaly detection and containment, when did it take effect, and what should you do if a user is frozen after a containment action? It explains the detection and notification process, the containment actions, and how to resolve a login containment event.

When Did This Change Take Effect

Salesforce applied this change in early April 2026. You may also have received notifications in early March 2026 when Salesforce enabled this change on a temporary basis.

The existing Login Anomaly feature included in Shield Threat Detection will continue to operate through at least June 30, 2026. In rare cases, customers may see duplicate detections between the two methods.

Detection and Notification

Salesforce monitors login behavior, specifically for network activity, client, authentication events, and geolocation tags. When Salesforce detects certain novel usage patterns in that behavior, including certain uses of anonymizing proxies, it notifies admins for affected instances of an anomaly detection and takes steps to contain the subject user. Salesforce also notifies admins (users with Modify All Data permissions) when it observes certain novel usage patterns in these behaviors in the absence of anonymizing proxies, which can also indicate suspicious login activity.

Containment Actions

Salesforce triggers the following actions when it detects significantly abnormal patterns in login behavior:

  • The user is automatically frozen, effectively terminating all sessions granted to that user and leaving them without access until a Salesforce Administrator unfreezes them.
  • Any remaining access and refresh tokens granted to that user are then revoked.
  • If the user authenticates with a password, they are required to reset that password after the Salesforce Administrator unfreezes them.
  • An email titled "Salesforce Security notification" is delivered to either Security Contacts (when populated) or users associated with the impacted org that have Modify All Data (MAD) permissions.

Resolve Login Containment Events

If you receive an email about a containment action, review the activity detailed in the email and take these steps:

  • If you recognize the affected login, instruct the user to avoid the use of VPNs with anonymizing proxies. If your business processes require the use of an anonymizing proxy, open a case with Salesforce Customer Support through Salesforce Help to discuss alternatives.
  • If you do not recognize the affected login, ensure that Multi-Factor Authentication (MFA) is strictly enforced for the user.
  • Review your logs for evidence of unauthorized activity. For a structured approach to analyzing Salesforce logs, see the Salesforce Log Analysis Guide in Salesforce Help.

My org only has one Admin and has been locked out due to an automated containment. How do I get back in?

If the org's only Admin is locked out and you cannot restore the affected user account, contact Salesforce Support for assistance. If needed, you can find Salesforce Customer Support phone numbers through the Contact Salesforce Support link in Additional Resources.

Knowledge-artikkelnummer

005319571

 
Laster
Salesforce Help | Article