阿里云上的Salesforce 关于事务安全策略(TSP)增强的变更及准备工作

更新时间:
复制 MD 格式

描述

为了提供更强的基线保护以防止数据外泄,Salesforce 正在为所有符合条件的 Salesforce Shield 和/或Event Monitoring (EM) 客户,推出一项应用于 ReportEvent 的默认事务安全策略 (Transaction Security Policy, TSP)。

变更内容

  • TSP 管理权限:Salesforce 新增了一项名为“Modify Transaction Security Policy”的用户权限。若要创建、更新、删除、启用或禁用 TSP,用户必须同时拥有“Modify Transaction Security Policy”和“Customize Application”这两项权限。此外,通过用户界面 (UI) 对 TSP 执行创建、更新、删除、启用和禁用等操作时,还需要进行增强身份认证。

  • 默认 ReportEvent TSP:Salesforce 正在为符合条件的客户引入并启用一个默认的 TSP,该策略针对通过用户界面 (UI) 发起的报告导出操作。当单次导出报告的记录数超过 10,000 条时,此策略便会被触发。此类报告导出活动同样需要进行增强身份认证。

Salesforce 为何做此项变更

大量报告的导出是恶意或无意的数据外泄的一个常见途径。此项变更通过 Event Monitoring 升级了保护措施,旨在利用事务安全策略 (TSP) 的控制措施来主动防止恶意或无意的数据外泄。

此变更的生效时间

新权限和默认 TSP 的强制执行时间

  • 预览沙盒环境(CHN5S):2026 年 8 月 10 日当周

  • 非预览沙盒(CHN3S) + 生产环境(CHN1 & CHN20):2026 年 8 月 31日当周

影响范围

  • 所有 Event Monitoring 客户,包括拥有 Salesforce Shield 或独立 EM 许可证的客户,只要他们在沙盒和生产环境组织中,尚未使用条件构建器 (condition builder) 构建现有的 ReportEvent TSP。

  • 创建、更新、删除、启用或禁用 TSP 的用户。

  • 通过 Salesforce UI 执行报告导出,且导出记录超过 10,000 条的用户。

预期情况

  • 对于 TSP 管理:只有同时拥有“Customize Application”和新的“Modify Transaction Security Policy”这两项权限的用户,才能对 TSP 执行创建、更新、删除、启用和禁用操作。仅拥有“Customize Application”权限的所有其他用户将获得只读访问权限。如果组织的可配置“Step-up Authentication period”已过期,当通过 UI 对任何 TSP 进行创建、更新、删除、启用或禁用操作时,将需要成功完成一次步进式身份认证。

  • 对于报告导出:当通过 UI 进行的报告导出超过 10,000 条记录时,默认的 TSP 将被触发,这将要求用户完成一次步进式身份认证。

解决方案

强制执行前的准备工作

在 Salesforce 将这些变更部署到您的组织中后:

  • 请审查您当前管理 TSP 的用户。若要让他们能够继续创建、更新、删除、启用或禁用 TSP,请为他们分配新的“Modify Transaction Security Policy”权限,并确保他们已配置了步进式身份认证。

  • 请在沙盒环境中审查默认处于禁用状态的 TSP(如果它已在您的组织中部署)。测试此策略,以确保它符合您的安全用例。然后,您可以选择启用或修改它。

注意:即使在自动强制执行后,该策略仍将保持完全可编辑。

强制执行后的异常解决

  • 对于 TSP 权限管理:

    • 权限检查 : 请确保用户在拥有“Customize Application” 权限的基础上,还被分配了新的“Modify Transaction Security Policy”权限。

    • 身份认证检查 : 如果创建、更新、删除、启用和禁用操作被阻止,请询问用户是否收到了重新进行身份认证的提示。该步进式身份认证是完成以上操作所必需的。

  • 对于报告导出: 如果在默认的 ReportEvent 策略被触发时,用户尚未配置步进式身份认证,则报告导出将被阻止。系统会提示用户先设置步进式身份认证,然后才能完成导出。

常见问题

问:如果我已经有一个 ReportEvent 策略该怎么办?

答: 如果您的组织中已有一个使用条件构建器 (condition builder) 创建的 ReportEvent TSP 策略,那么默认策略就不会被部署。否则,默认策略将被部署为一个新的、禁用的、独立的策略,并且不会影响任何现有的(无论激活或禁用状态的)事务安全策略。您可以审查、编辑或禁用默认的 ReportEvent 策略。如果组织中已存在另一个 ReportEvent 策略,Salesforce 将不会自动启用该默认策略。

问:在强制生效日当天,我仍在测试默认策略,该怎么办?

答: 如果您以任何形式编辑过默认策略,Salesforce 就会认为您正在审查该策略,因此不会自动启用它。

问:强制生效后,默认的 TSP 是被永久启用,还是可以更改?

答: 默认的 TSP 不会被永久强制执行。在强制生效之前或之后,您随时可以对其进行编辑、修改或禁用。

问:默认的 TSP 是否会影响 Data Loader CLI 或基于 API 的报告导出?

答: 不会。默认的 TSP 仅适用于通过 Salesforce UI (用户界面) 执行的报告导出。它不影响通过 API 执行的报告导出,包括 Data Loader CLI 和其他基于 API 的报告导出。

问:即使管理员已拥有新的“Modify Transaction Security Policy” 权限,在编辑 TSP 时是否仍会触发步进式身份认证?

答: 是的,步进式身份认证仍会被触发。除非他们之前已经完成了步进式身份认证,并且当前仍处于在“Session Level Policy level ”中设置的步进式身份认证有效期内。

Description

To provide enhanced baseline protection against data exfiltration, Salesforce is rolling out a default Transaction Security Policy (TSP) on ReportEvent for all eligible Salesforce Shield and/or Event Monitoring (EM) customers.

What's Changing

  • TSP Management Permission: Salesforce is introducing a new Modify Transaction Security Policy user permission. To create, update, delete, enable, or disable TSPs, both the Modify Transaction Security Policy and Customize Application permissions are required. Create, update, delete, enable, and disable operations on TSPs via UI will also require step-up authentication.

  • Default ReportEvent TSP: Salesforce is introducing and enabling a default TSP for report exports initiated through the UI for eligible customers. This policy is triggered when an export exceeds 10,000 records. Such report export activities will also require step-up authentication.

Why Is Salesforce Making This Change

Large report exports are a common vector for malicious or unintended data exfiltration. This change upgrades protection via Event Monitoring to actively prevent malicious or unintended data exfiltration through TSP controls.

When Does This Change Take Effect

Enforcement of new Permission and default TSP

  • Preview Sandboxes(CHN5S): Week of August 10, 2026.

  • Non-Preview Sandboxes(CHN3S) & Production(CHN1&CHN20):  Week of August 31, 2026

Who's Affected

  • All Event Monitoring (EM) customers, including those with Salesforce Shield or standalone EM licenses, in both sandbox and production orgs who don't have an existing ReportEvent TSP built using condition builder.

  • Users who create, update, or delete, enable or disable TSPs.

  • Users who perform report exports that exceed 10,000 records via the Salesforce UI.

What to Expect

  • For TSP Management: Only users with both the Customize Application and the new Modify Transaction Security Policy permissions will be able to perform create, update, delete, enable, and disable operations on TSPs. Read-only access will be granted to all other users having only the Customize Application permission. If the org's configurable Step-up Authentication period has expired, successful re-authentication via step-up authentication will be required when any TSP is created, updated, deleted, enabled, or disabled via UI.

  • For Report Exports: When a report export via UI exceeds 10,000 records, the default TSP will be triggered which will require the user to complete a step-up authentication.

Resolution

Before Enforcement: How to Prepare

After Salesforce deploys the changes in your org:

  • Review your current users who manage TSPs. To allow them to continue to create, update, or delete, enable or disable TSPs, assign them the new Modify Transaction Security Policy permission and ensure that they have step-up authentication configured.

  • Review the default disabled TSP in a sandbox, if it has been deployed in your org. Test this policy to ensure it aligns with your security use cases. You can then choose to enable or modify it.

Note: The policy will remain fully editable even after automatic enforcement.

After Enforcement: Resolve Errors

  • For TSP Permission management :

    • Permission Check: Ensure that the user has been assigned the new Modify Transaction Security Policy permission, in addition to the Customize Application permission

    • Authentication Check: If a create, update, delete, enable, and disable action is blocked, ask the user whether they were prompted to re-authenticate. That step-up authentication is required to complete the operation.

  • For Report Exports: If step-up authentication isn't configured for a user when the default ReportEvent policy is triggered, the report export will be blocked. The user is prompted to set up step-up authentication before the export can be completed.

Common Questions

What if I already have a ReportEvent policy?

If a ReportEvent TSP policy built using condition builder already exists, then the default policy will not be deployed in your org. Otherwise, the default policy will be deployed as a new, disabled, separate policy and will not impact any existing Transaction Security Policies, whether active or disabled. You can review, edit, or disable the default ReportEvent policy. Salesforce will not automatically enable the default policy if another ReportEvent policy already exists in the org.

What if I am still testing the default policy by enforcement date?

If you have edited the default policy in any form, Salesforce will assume you are reviewing the policy hence it won't auto enable.

After enforcement, is the default TSP permanently enabled, or can it be changed?

The default TSP is not permanently enforced. You can edit, modify, or disable it at any time before or after enforcement takes effect.

Does the default TSP affect Data Loader CLI, API-based report exports?

No. The default TSP applies only to report exports performed through the Salesforce UI. It does not affect report exports performed via API, including Data Loader CLI, and API-based report exports.

Does a step-up authentication challenge still trigger when editing a TSP even after the admin has the new Modify Transaction Security Policy permission?

Yes, the step-up authentication will trigger, unless they previously completed step-up authentication and are still in an active step-up authentication period set at the Session Level Policy level.