top of page

Salesforce Winter '27 Release Notes: What Admins and Developers Need to Know

  • Writer: Kris Var
    Kris Var
  • 31 minutes ago
  • 4 min read

Per Salesforce's own Admin Release Countdown, Winter '27 production upgrades land September 4, October 2, and October 9, 2026, with the exact date for any given org on Trust Status's Maintenance Calendar (search your instance, NA__ or EMEA__, against the listed dates). Release notes publish August 19. Sandbox preview begins August 28, with an August 27, 5 p.m. Pacific deadline to refresh a non-preview-slated sandbox for early access. A handful of Release Updates that enforce in Winter '27 are already locked in and documented today on help.salesforce.com, forward-announced in the Summer '26 release notes the way most releases work. This rounds up those confirmed updates, each sourced directly from Salesforce's own documentation, plus one correction worth knowing before you plan around it.


Confirmed Release Updates enforcing in Winter '27


Enable Profile Filtering. Affects anyone whose flows, formulas, validation rules, or reports reference another user's Profile Name. Risk if ignored: that functionality breaks for users without the View All Profiles permission.


Modify Transaction Security Policy Permission. Affects orgs with Event Monitoring or Shield using Transaction Security Policies. Risk if ignored: admins with only Customize Application drop to view-only on TSPs.


Adopt Authorized Email Domains. Affects orgs that had Support disable Email Change Verification, or plan a bulk update of user email addresses. Risk if ignored: bulk email address changes start requiring per-user re-verification.


3 Accessibility Enhancement updates (page headers/modals; date pickers, popovers, utility bars, record headers; cards, docked containers, menu lists, panels). Affects users viewing Salesforce at 200%+ browser zoom. Risk if ignored: content clips or overlaps for users who rely on magnification.


Update Instanced URLs in API Traffic. Affects integrations using a hard-coded instanced URL instead of the org's My Domain login URL. Risk if ignored: API calls using the old URL stop working once enforcement phases in.


Enable Profile Filtering


Users currently see other people's Profile Names without needing the View All Profiles permission. This update restricts that to users who have it. Before enforcement, audit your flows, reports, formulas, and other customizations for anywhere that references another user's Profile Name, refactor what depends on it, and grant View All Profiles only where refactoring isn't feasible.


Modify Transaction Security Policy Permission


A new, narrower permission takes over creating, editing, and deleting Transaction Security Policies. Customize Application alone no longer grants edit access. Confirm which of your admins actually need to manage TSPs and assign the new permission to them specifically, rather than assuming Customize Application still covers it.


Adopt Authorized Email Domains


Salesforce is retiring the manual exemption process Support used to grant for disabling Email Change Verification. The replacement is self-service: a DKIM key or an Authorized Email Domain configured under Email Administration in Setup. If your org never used that exemption, this update doesn't change anything for you. If it did, or a bulk email update is planned, set up the DKIM key or authorized domain now and run the update's test run in a sandbox first. This only affects verification of email address changes; there's no change to Salesforce account-login verification.


Accessibility enhancements at high zoom


Three related updates bring Lightning Experience toward WCAG 2.2's Resize and Reflow requirements at up to 400% browser magnification. Salesforce requires enabling them in order, with the page headers/modals update first, since the other two depend on it. Test each one in a sandbox at 200% and 400% zoom, in the required order, before enabling in production. If nobody at your org routinely tests at that zoom level, check usage patterns first: users with low vision are more likely to run at high magnification than most admins expect.


Update Instanced URLs in API Traffic


Originally scheduled for Spring '26, this was postponed to Winter '27. It ends support for API traffic that uses a hard-coded instance name instead of the org's My Domain login URL, which matters for any integration, middleware connection, or custom API client your team maintains. Audit API endpoints in your integrations for hard-coded instance URLs and switch them to the My Domain login URL. Enforcement then rolls out in phases after Winter '27 deployment, with a separate end-of-support schedule for exact dates.


Correction: the OAuth Username-Password Flow retirement isn't Winter '27 anymore


The retirement of the OAuth 2.0 Username-Password Flow for Connected Apps has circulated as a Winter '27 enforcement. Salesforce's own release note, checked directly while researching this piece, now says otherwise: "Salesforce enforces this update on February 20, 2027. This update was first announced in Spring '26. It was originally scheduled to be enforced with the Winter '27 major release, but we changed the enforcement date." If any integration in your org still uses that flow, fix it before it breaks. The deadline just isn't a Winter '27 one.


General prep, regardless of which update


Test in a sandbox first, in the order Salesforce specifies: several of these updates, the accessibility trio especially, have explicit sequencing requirements. Check Trust Status for your instance's actual upgrade date, not a calendar month printed in any guide, including this one. Check in with managed-package vendors, since part of a package's configuration isn't visible to you as a subscriber and a Release Update can affect it in ways you can't audit from the outside. And recheck Setup → Release Updates close to your enforcement date. Salesforce revises scope and timing after first publishing an update regularly enough that the OAuth correction above shouldn't be treated as a one-off.


For a deeper dive on the two permission-shaped changes here, Profile Filtering and the Transaction Security Policy permission, see the Winter '27 permission readiness piece. Or start at the Power User Toolkit overview.


Recent Posts

See All

Comments


bottom of page