Opt Out of Enforcing Guest User Object Permission Changes (Previously Released Update)

For Salesforce orgs created before Winter ’21, this update opts your org out of enforcing guest user object permission changes aimed at increasing your data security.

Where: This update applies to all Salesforce Sites (formerly Force.com Sites), Site.com sites, and communities that have guest user access enabled.

Why: Activating the Opt Out of Enforcing Guest User Object Permission Changes update keeps the following permissions unchanged. If they are enabled, they remain enabled, and if they are disabled, they remain disabled.
  • Edit, delete, Modify All Data, and View All Data for custom objects.
  • Edit, delete, Modify All Data, and View All Data for the following standard objects: Order, Contract, Survey Response, ProfileSkillUser, and ProfileSkillEndorsement.

    These permissions are scheduled to be turned off for custom objects and the previous standard objects with the rollout of the Winter ’21 release. But you can still enable them to meet your business needs. After your org updates with the Winter ’21 release, you can no longer activate this update.

    If you opt out, your opt-out period is only valid for the Winter ’21 release. With the Spring ’21 release, these permissions are permanently removed for guest users, and can no longer be enabled.

    Salesforce strongly recommends that you closely check your org’s guest user profiles, permission sets, and permission set groups to ensure that the settings aren’t enabled for any standard or custom objects. If the settings are enabled, disable them, and test your org’s configuration before the Winter ’21 release. Salesforce understands that some customers require more time to comply with removing the permissions from guest user profiles. This update gives you ample time to get ready.

    Important

    Important

    If a permission set or permission set group is assigned to the guest user and grants edit, delete, Modify All Data, or View All Data to custom objects, or Order, Contract, Survey Response, ProfileSkillUser, and ProfileSkillEndorsement, then the guest user is removed from the permission set or permission set group. If any other permissions were granted using the same permission set or permission set group, the guest user can no longer access them. Use this opt-out to stop the removal of the guest user from permission sets or permission set group. If your guest user is removed with the Winter ’21 release, you can simply reassign the guest user to the permission set or permission set group. But starting with the Spring '21 release, you can no longer assign Modify All Data, View All Data, edit, or delete permissions to guest users, even with a permission set or permission set group.