iTnews Asia
  • Home
  • News
  • Cloud

Salesforce cloud outage caused by security change

Salesforce cloud outage caused by security change

Goes public with post-mortem.

By Richard Chirgwin on Sep 27, 2023 12:23PM

A widespread Salesforce outage last week was caused by the rollout of a new permissions policy as part of defence-in-depth efforts that mistakenly locked users out of their accounts.

The four-hour outage on September 21, took out a number of Salesforce 'Clouds', along with Tableau and MuleSoft.

In a root cause analysis, published late last week, Salesforce revealed the outage was caused by an access permissions change.

"The change had unintended consequences," Salesforce wrote.

"While it was designed to add defence-in-depth, it inadvertently blocked access to other legitimate and necessary resources beyond its intended scope.

"The end result was a breakdown in communication between our services due to a lack of access permissions, causing failures within our systems.

"This restricted some of our customers from logging in and using the services."

The company explained that its "standard operating procedure mandates ongoing reviews and updates to security controls.

The change, the company admitted in its analysis, “was not identified in validation testing”, because whatever it changed couldn’t be pre-tested: “the standard change deployment pipeline could not be used to deploy this change.”

That meant a particular characteristic of the change wasn’t caught: that it was “applied at a level that impacted multiple systems”. 

Had the change fitted within Salesforce’s “automated deployment process … the change would only have affected a small number of services”.

Salesforce said this will be addressed with a new deployment and testing pipeline later this year.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
cloud salesforce security

Related Articles

  • The ROI for AI needs to be redefined, says Hitachi Vantara’s CTO
  • Thailand’s Roojai unifies operations, nearly doubles sales per agent
  • Smart Communications unifies digital storefront for over 50M subscribers
  • The best way to outsmart your threat actors is to think like one
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Sony Pictures India uses data lake to modernise downstream applications

Sony Pictures India uses data lake to modernise downstream applications

Tips to modernise cloud architecture for scalable digital transformation

Tips to modernise cloud architecture for scalable digital transformation

Smart Communications unifies digital storefront for over 50M subscribers

Smart Communications unifies digital storefront for over 50M subscribers

Thailand’s Roojai unifies operations, nearly doubles sales per agent

Thailand’s Roojai unifies operations, nearly doubles sales per agent

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.