You are here:
Monitor and Audit Security in Salesforce
Salesforce security is an ongoing practice. Audit changes to your org’s security, including field and setup changes. Track user logins, mobile device access, and user identity verification events.
- Monitor Setup Changes with Setup Audit Trail
Setup Audit Trail tracks the recent setup changes that you and other admins make. Audit history is especially useful when there are multiple admins. - Monitor Login History
As an admin, you can monitor all attempts to log in to Salesforce and to your Experience Cloud sites. The Login History page shows up to 20,000 records of user logins for the past 6 months. To see more records, download the information to a CSV or GZIP file. - Monitor Identity Verification History
Use Identity Verification History to monitor and audit up to 20,000 records of your org users’ identity verification attempts from the past 6 months. For example, when a user successfully provides a time-based, one-time password (TOTP) as proof of identity during multi-factor authentication (MFA), that information is recorded in Identity Verification History. - See How Your Users Verify Their Identity
To see who's using which identity verification methods, customize a list view of your users or create an Identity Verification Methods report.Use custom reports to spot patterns in identity verification behavior for your org or Experience Cloud site. - Field History Tracking
To maintain an audit trail of who changed what and when, use Field History Tracking. Select the standard and custom object fields to track. - Monitor Debug Logs
Set trace flags to trigger logging for users, Apex classes, and Apex triggers in the Developer Console or in Setup. Monitor the resulting logs to diagnose problems in your org. - Mobile Device Tracking
Mobile Device Tracking gives you greater control over your data security. You can track and monitor which mobile devices access your Salesforce org. You can revoke access from lost and stolen devices. And you can build processes and policies to define how devices access your org, such as requiring an approval request from the device before authorizing a login.

