Newer Version Available
TransactionSecurityPolicy
This type extends the Metadata metadata type and inherits its fullName field.
File Suffix and Directory Location
TransactionSecurityPolicy components have the suffix .transactionSecurityPolicy and are stored in the transactionSecurityPolicies folder.
Version
TransactionSecurityPolicy components are available in API version 35.0 and later.
Fields
| Field Name | Field Type | Description |
|---|---|---|
| action | TransactionSecurityAction | Required. Describes the action to take when the matching Transaction Security policy is triggered. |
| active | boolean | Required. If true, the policy is enabled and actively monitors its event. |
| apexClass | string | Required for Apex-based policies, and optional for all other policies. The name of the class that implements the TxnSecurity.PolicyCondition or TxnSecurity.EventCondition interface for this policy. Available in API version 46.0 and later. |
| blockMessage | string | The custom message sent to a user when a policy blocks their action. Used in
Real-Time Event Monitoring only. Maximum of 1000 characters. This field is null when
the default message option is selected in the UI.. Available only when
eventName is set to ApiEvent, ListViewEvent, BulkApiResultEventStore, or ReportEvent. Available in API version 49.0 and later.
Include org- or policy-specific information in your custom message, such as the name of the responsible administrator or the business unit. Be careful about what you include. Too much information on how the policy was designed. can aid a malicious user. Two-factor authentication (2FA) isn’t supported in Lightning Experience, so events like ListView and ReportEvent are upgraded to Block in Lightning. Custom messages aren’t translatable. |
| description | string | A description of the policy. |
| developerName | string | This unique name prevents conflicts with other policies that have the same masterLabel. This name can contain only underscores and alphanumeric characters, and must be unique in your org. It must begin with a letter, not include spaces, not end with an underscore, and not contain two consecutive underscores. |
| eventName | TransactionSecurityEventName (enumeration of type string) | Used in Real-Time Event Monitoring only. Indicates the name of the event the
policy monitors. This field is available in API 45.0 and later. Valid values are:
|
| eventType | MonitoredEvents (enumeration of type string) | Used in Legacy Transaction Security only. Required for Apex-based policies, and
optional for all other policies. Indicates which type of event is being monitored.
Valid values are:
|
| executionUser | string | Used in Legacy Transaction Security only. The name or ID of an active user who is assigned the Modify All Data and View Setup user permissions. |
| flow | string | Required only for policies of type CustomConditionBuilderPolicy. The ID of the Flow object that contains the logic the Condition Builder transaction security policy. Available in API version 46.0 and later. |
| masterLabel | string | The master label for this object. This display value is the internal label that is not translated. |
| resourceName | string | Used in Legacy Transaction Security only. Required for Apex-based policies, and
optional for all other policies. A resource used to narrow down the conditions under
which the policy triggers. For example, with a DataExport event, you can select a resource Lead to specifically monitor
export activity occurring on your Lead entities. The resources available depend on
the Event Type field. The following valid
resources are grouped by event type.
|
| type | TxnSecurityPolicyType (enumeration of type string) | The type of validation that the policy uses. The valid values are:
|
TransactionSecurityAction
Describes the action to take when the matching Transaction Security policy is triggered.
| Field Name | Field Type | Description |
|---|---|---|
| block | boolean | If true, the requested operation is blocked. This action only applies to Login and AccessResource events. |
| endSession | boolean | Used in Legacy Transaction Security only. If true, a current session must be closed before a new session can be started. This action only applies to Login events. |
| freezeUser | boolean | Used in Legacy Transaction Security only. If true, the user that triggered the policy is frozen. This action only applies to Chatter resources for Entity events. |
| notifications | TransactionSecurityNotification[] | Specifies how to notify the Salesforce administrator when the action is triggered. There can be none, one, or multiple notifications. |
| twoFactorAuthentication | boolean | If true, multi-factor authentication (MFA) is required for a higher level of access before the requested operation can continue. This action only applies to Login and AccessResource events. |
TransactionSecurityNotification
Describes who to notify and how to notify them when the matching Transaction Security policy is triggered.
| Field Name | Field Type | Description |
|---|---|---|
| inApp | boolean | True if an in-app notification is selected. |
| sendEmail | boolean | True if an email notification is selected. |
| user | string | The user to receive the notification. |
Declarative Metadata Sample Definition
The following is an example of a Real-Time Event Monitoring TransactionSecurityPolicy component.
1<?xml version="1.0" encoding="UTF-8"?>
2<TransactionSecurityPolicy xmlns="http://soap.sforce.com/2006/04/metadata">
3 <action>
4 <block>true</block>
5 <notifications>
6 <inApp>true</inApp>
7 <sendEmail>true</sendEmail>
8 <user>user@your.org</user>
9 </notifications>
10 <twoFactorAuthentication>false</twoFactorAuthentication>
11 </action>
12 <active>true</active>
13 <apexClass>TxnSecMDApiPolicyEventCondition</apexClass>
14 <blockMessage>You cannot view this report.</blockMessage>
15 <developerName>TxnSecPolicyMDApi</developerName>
16 <eventName>ReportEvent</eventName>
17 <masterLabel>Txn Sec MD Api Policy</masterLabel>
18 <type>CustomApexPolicy</type>
19</TransactionSecurityPolicy>The following is an example package manifest used to deploy or retrieve the transaction security metadata for an organization.
1<?xml version="1.0" encoding="UTF-8"?>
2<Package xmlns="http://soap.sforce.com/2006/04/metadata">
3 <types>
4 <members>MySecurityPolicy</members>
5 <name>TransactionSecurityPolicy</name>
6 </types>
7 <version>35.0</version>
8</Package>Wildcard Support in the Manifest File
This metadata type supports the wildcard character * (asterisk) in the package.xml manifest file. For information about using the manifest file, see Deploying and Retrieving Metadata with the Zip File.