Subset of Salesforce posture rule unexpectedly changed to passing

Incident Report for Obsidian Security

Resolved

The issue has been resolved and impacted Salesforce posture rules now reflect the correct status. We appreciate your patience and understanding during this time, and if you experience any further issues, please do not hesitate to reach out.
Posted Aug 28, 2025 - 16:05 PDT

Identified

We have identified an issue impacting a subset of Salesforce posture rules. Impacted customers may find that the rule IDs noted below will have unexpectedly moved from a failing to passing state. In the course of addressing the underlying cause, and rules being reverted to their proper state, posture drift alerts may be received.

Environments Impacted: US, EU, AU

SalesforceInactivePrivilegedAccounts
SalesforceSystemAdmins
SalesforcePrivilegedUsersFromLowReputationDomains
SalesforceGhostAdmins
SalesforceUsersWithCreatePublicLinks
SalesforceWeakerProfilePasswordSettings
SalesforceExternalUserObjectAccess
SalesforceUsersWaivedMFA
SalesforceGuestUserObjectAccess
SalesforceUsersNoMFA
SalesforceIntegrationUsersWithSysAdminProfile
SalesforceRiskyGuestUsers
SalesforceFieldLevelAccessForEncryptedData
SalesforceWeakerProfileSessionSettings
SalesforceFieldLevelAccessForComplianceData
SalesforceAppsExcessivePermissions


Additional updates will be provided via this posting as our investigation progresses and the issue is mitigated.
Posted Aug 28, 2025 - 09:06 PDT
This incident affected: Posture Management.