Loading
Salesforce now sends email only from verified domains. Read More
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Advanced Security Checks for Omnistudio for Managed Packages

          Advanced Security Checks for Omnistudio for Managed Packages

          Advanced security checks for Omnistudio for Managed Packages enhance data protection by enforcing stricter validation of access and permissions. When enabled, these checks validate object-level access, field-level security, and Apex class permissions for all users, including guest, authenticated, and non-authenticated users, across Omnistudio components.

          These security enhancements are available starting with the Winter '26 and Spring '26 releases.

          These feature flags control the advanced security checks:

          • AdvancedOmnistudioAccessCheck
          • ApexClassCheckForIP

          For more information about ApexClassCheckForIP, see Advanced Apex Class Check for Integration Procedures in Omnistudio for Managed Packages.

          The advanced security checks apply only when the flags are enabled.

          In addition to the AdvancedOmnistudioAccessCheck and ApexClassCheckForIP flags, Omnistudio supports these previously announced security flags:

          • ApexClassCheck
          • EnforceDMFLSAndDataEncryption
          • EnableQueryWithFLS

          Salesforce continues to recommend enabling them to support consistent enforcement of data access and security controls across Omnistudio components.

          Important
          Important During the week of February 2, 2026, Salesforce enables the AdvancedOmnistudioAccessCheck, ApexClassCheckForIP, ApexClassCheck, EnforceDMFLSAndDataEncryption, and EnableQueryWithFLS settings by default to enhance org security. Review and prepare your configuration for a seamless transition and to prevent potential service interruptions.

          When the advanced security checks are enabled, users must have the appropriate object permissions, field-level security, and Apex class access for the data and logic used within Omnistudio components. If the required permissions aren’t assigned, users may experience issues accessing or interacting with Omnistudio data.

          For information about the permissions required when the AdvancedOmnistudioAccessCheck feature flag is enabled, see Omnistudio Component Access Issues and Potential Causes.

          How to Enable Security Flags in Omnistudio

          The steps to enable security flags and the location of the settings depend on whether the org has an Omnistudio license and whether it uses a custom data model or standard data model. Depending on your org's Omnistudio license status and data model, locate and configure the flags. For information about data models, see Omnistudio Data Models, Does Your Org Use Custom or Standard Objects?.

          • In orgs without an Omnistudio license or orgs still using custom data model:

            1. From Setup, in the Quick Find box, enter Custom Settings, and then select Custom Settings.
            2. Click G and go to General Settings.
            3. Click Manage.
            4. Click New.
            5. In the Label field, enter AdvancedOmnistudioAccessCheck or ApexClassCheckForIP.
            6. In the Value field, enter true.
          • In orgs with an Omnistudio license using the standard data model:

            1. From Setup, in the Quick Find box, enter Omni Interaction Configuration, and then select Omni Interaction Configuration.
            2. Click New Omni Interaction Configuration.
            3. In the Label field, enter AdvancedOmnistudioAccessCheck or ApexClassCheckForIP.
            4. In the Value field, enter true.
           
          Loading
          Salesforce Help | Article