Celebrate 20 years of the Trailblazer Community with us on Social!

Securing Public Access Controls in Aura Experience Cloud Sites

Mar 31, 11:00 PM – Apr 1, 12:00 AM (UTC)

Salesforce User Group, Wellington, New Zealand

🚨 Could your Salesforce Experience Cloud site be exposing data without you realising? With recent reports of threat groups exploiting misconfigured systems and increased focus on public access in Aura Experience Cloud sites, now’s the time to take a closer look at your own setup.

Experience CloudPlatform

About this event

THANKS FOR ATTENDING ANOTHER GREAT SESSION WITH DOUG...

RECORDINGhttps://us02web.zoom.us/rec/share/B6PFD24BOIEOwQ-woR6uG6PP3g5YF9Lr-B6pkucVAmJWqcVPQ2EA-0zfmOi_4C6e.48LeDErK4xMbrVR_?pwd=DEVEzlneb5i4-jdgtAAAIAAAAAxPtv4Kkz32cX69yV-sEvd2QFy2zFtLxXX4RqxqSgnxTVvcr624BHT-ViL7NMQAEDAwMDAwNA

MEETING SUMMARY (AI): https://docs.zoom.us/doc/nxwfUP-eSDKupzEHYdYeuQ?from=doc_share&skipCheck=1

Links:

https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/

We’re bringing back Doug Merrett, Melbourne-based Salesforce security expert, to break down what’s really happening, and how to make sure your Experience Cloud site isn’t unintentionally sharing more than it should.

In this session, Doug will cover:
🌐 How public access works in Aura sites (and where things can go wrong)
🔍 How to check if your org is exposed
⚠️ Common misconfigurations that can lead to unintended data access
🛠 Practical ways to lock things down using standard Salesforce features

EXTRA EXTRA!!! We’ll also touch on upcoming Salesforce security enhancements, with Doug providing context on what they mean in practice.

Salesforce is introducing stronger controls across areas like:
🔐 User identity – including mandatory MFA and phishing-resistant MFA
🛡️ Data protection – with added verification for sensitive actions like bulk exports
🌐 Adaptive access – using risk-based checks for users and devices

There are also important changes coming soon, including email domain verification requirements to help prevent spoofing and phishing, along with additional security controls being enforced from June 2026.

Doug will cover what’s changing, why it matters, and how you can get ahead of these updates.

Expect a session that’s practical, eye-opening, and a timely reminder that security is not something to take lightly.

🎟️ Register now for a VIRTUAL SESSION and protect your data!


Meeting summary (AI generated) Quick recap

Doug presented a comprehensive security assessment focused on guest user access in Salesforce communities, highlighting critical security risks and mitigation strategies. He explained that guest users should have zero read access to prevent data breaches, and demonstrated how to identify and fix problematic sharing configurations using tools like the Authenticator and Guest User Access Report from the AppExchange. The discussion covered specific settings to review, including org-wide default sharing, Aura-exposed methods, and Enhanced Personal Information Masking configurations. Doug recommended developing new communities using Lightning Web Runtime instead of Aura to avoid known security issues, and offered a special security assessment discount for Wellington Salesforce User Group members.

Next steps

- All org admins: Install and run the Authenticator and Guest User Access Report app from AppExchange in production (or in a full copy sandbox if production install is not possible), and review guest user access settings as per Doug's recommendations

- All org admins: If the report or built-in Guest User Sharing Rule Access Report in setup reveals inappropriate guest user read access, immediately restrict access and consider shutting down the community until fixed

- All org admins: Ensure org-wide default sharing for external users is set to private for all relevant objects, except where explicitly approved by security

- All org admins: Review and remove/rectify any sharing rules that grant guest users read access, except for justified cases (e.g., knowledge base, store locations)

- All org admins: For Aura-exposed Apex methods, ensure "without sharing" is not used unless absolutely necessary and safe

- All org admins: Check and, if not already enabled, turn on "Secure guest user record access" in Sharing Settings

- All org admins: Review user visibility settings and ensure guest users cannot see user object data unless required

- All org admins: Review Enhanced Personal Information Masking (EPIM) configuration as highlighted by Raksha

- All org admins: For new community builds, use Lightning Web Runtime instead of Aura, where possible

- All org admins: If using Omniscript or similar functionality, review sharing settings to ensure only necessary data is exposed and understand the risks

- All org admins: If security review is conducted, follow up on findings by implementing recommended fixes or contacting Doug for clarification if needed

- All org admins: If unable to install AppExchange tool, use the built-in Guest User Sharing Rule Access Report in setup as an initial check, and use findings to justify installation of the more detailed tool to security teams

Summary

Salesforce Guest User Security Concerns

Doug discussed security concerns with guest user access in Salesforce, particularly highlighting the risk of granting read access to guest users. He explained that while zero read access is ideal, there are specific use cases where read access might be acceptable, such as knowledge bases or store location data. Doug recommended using the Authenticator and Guest User Access Report tool to identify and fix any inappropriate guest user access, emphasizing that org-wide default sharing for external users should be set to private and that sharing rules should not override this setting. He advised that if security issues are severe, communities should be temporarily shut down until fixes can be implemented.

Salesforce Guest User Security Discussion

The team discussed security concerns around guest user access in Salesforce communities, focusing on potential vulnerabilities with Aura methods and flow architecture. Doug recommended using a Mandiant tool from the AppExchange to test guest user permissions, though Anna noted this might not be possible in all corporate environments. The discussion highlighted that while guest users were the primary concern, authenticated users could also be affected if sharing settings aren't properly configured, with particular attention to URL shortcuts and Org Wide Default Sharing settings for external users.

Salesforce Community Security Best Practices

Doug discussed security considerations for Salesforce communities, highlighting the importance of using Lightning Web Runtime instead of Aura due to known security issues with Aura. He recommended reviewing the Enhanced Personal Information Masking (EPIM) configuration and disabling direct access to the user object for guest users. Doug also offered a Platinum 7 security assessment at a 10% discount for Welly SF user group members, and encouraged attendees to reach out with any security-related questions. Becky asked about the secure guest user record access checkbox in sharing settings, though the answer was not provided in the transcript.

Salesforce Guest User Sharing Configuration

Doug demonstrated how to configure guest user sharing settings in Salesforce, focusing on the "Secure Guest User Record" option under other settings which overrides org-wide defaults for guest users. He emphasized the importance of reviewing all sharing rules to ensure guest users don't have inappropriate access, particularly highlighting the need to check for any "shared with guest user" entries. Anna noted this type of configuration question is common in sharing and visibility architecture, while Rob added a caution about industry cloud settings that might inadvertently expose data through discovery frameworks.

Salesforce Security Settings Discussion

The team discussed security considerations around sharing settings in Salesforce, particularly regarding Omniscript and Velocity scripts. Doug advised checking why certain scripts are shared and assessing the risks, especially for account or contact data. Anna raised questions about YubiKeys, and Doug explained some potential vulnerabilities while recommending physical keys as a secure option. The discussion concluded with Doug clarifying that security reviews identify issues but don't implement fixes, leaving that to the client's team, and Raksha encouraged attendees to consider Doug's services for future security assessments.

Speaker

  • Doug Merrett

    Platinum7

    Founder | Principal Consultant

Group Leaders

  • Anna Loughnan

    Good Human

    Leader

  • Raksha Meanger

    Xero

    Community Group Leader

CONTACT US

Join your local Trailblazer Community Group, meet other developers & get best practices for building on the App Cloud

JOIN US