Salesforce Changed the TimeLine Not the Security Strategy
For the past few years, Salesforce administrators and IT teams have been preparing for a significant shift in user access management: the retirement of permissions managed directly through Profiles. Many organizations invested time and resources into planning their migration to a Permission Set based security model.
However, Salesforce has now announced that it is indefinitely postponing the retirement of Profile-based permissions after listening to customer feedback and recognizing that some capabilities still require further development.
While this announcement removes the immediate pressure to migrate, it does not change Salesforce’s long-term vision for security. Permission Sets and Permission Set Groups remain the recommended approach for managing user access because they provide greater flexibility, stronger governance, and align with the Principle of Least Privilege.

For business leaders, this isn’t simply a product update it’s an opportunity to rethink access management strategically rather than reactively.
Instead of asking:
“Do we still need to migrate away from Profile permissions?”
Organizations should be asking:
“How can we use this additional time to build a more secure, scalable, and future-ready Salesforce security model?”
The businesses that take a proactive approach today will reduce security risks, simplify administration, improve compliance, and be better prepared for future Salesforce innovationsall without the pressure of a mandatory migration deadline.
The Business Challenge
As Salesforce environments grow and evolve, so do their security and access management requirements. Over the years, many organizations have expanded their Salesforce implementations by introducing new business processes, custom applications, integrations, and user roles. In many cases, administrators continue to manage user access through Profiles simply because it has been the traditional and most familiar approach.
While this method may work in the short term, it often leads to increasingly complex permission structures that are difficult to maintain and govern. As organizations scale, relying heavily on Profile-based permissions can create operational inefficiencies and unnecessary security risks.
Some of the most common business challenges include:
- Excessive User Access: Employees may receive permissions beyond what their roles require, increasing the risk of unauthorized access to sensitive data.
- Complex Security Audits: Reviewing and validating user permissions becomes more time-consuming, making compliance audits more difficult.
- Inconsistent User Provisioning: Onboarding new employees often results in inconsistent permission assignments, leading to productivity issues or excessive access.
- Higher Offboarding Risks: Delays in removing unnecessary permissions can leave former employees or transferred users with unintended access.
- Administrative Overhead: Troubleshooting permission-related issues consumes valuable administrator time and slows business operations.
- Compliance and Governance Challenges: Meeting regulatory requirements and maintaining the Principle of Least Privilege becomes increasingly difficult as Profile configurations grow more complex.
These challenges are not dependent on Salesforce’s decision to postpone the retirement of Profile permissions. Regardless of the timeline, organizations that continue relying primarily on Profiles may face growing security, compliance, and operational challenges. Adopting a modern, Permission Set–driven approach enables businesses to simplify access management, strengthen governance, and build a scalable security model for the future.
What Changed?
Salesforce has officially cancelled the mandatory retirement of Profile-based permissions, giving organizations greater flexibility in how they manage user access. This decision follows customer feedback and acknowledges that some capabilities still require additional maturity before a complete transition away from Profiles can be enforced.

While the migration deadline has been removed, Salesforce’s strategic direction remains unchanged. The company continues to recommend Permission Sets and Permission Set Groups as the preferred approach for managing user permissions, enabling organizations to implement a more flexible, scalable, and secure access model.
Going forward, Profiles are expected to serve primarily as containers for baseline user settings, including:
- Login Hours
- Login IP Ranges
- Default Apps
- Default Record Types
- Page Layout Assignments
- Session Settings
Role-specific business permissions such as object access, field-level security, system permissions, and feature access should increasingly be managed through Permission Sets and Permission Set Groups. This approach allows organizations to assign access based on job responsibilities without creating numerous custom Profiles.

For businesses, this announcement should not be viewed as a reason to delay modernization. Instead, it provides an opportunity to transition to a Permission Set–driven security model at a controlled pace, reducing administrative complexity while improving governance and preparing for future Salesforce innovations.
Why This Matters for Business Leaders
With Salesforce cancelling the mandatory retirement of Profile-based permissions, some organizations may assume they can pause or abandon their migration plans. While this may appear to reduce effort in the short term, it can lead to increased operational complexity, security risks, and higher administrative costs over time.
Today’s businesses operate in an environment where strong security and efficient access management are critical. As organizations grow, they need a user access model that supports robust governance, enforces the Principle of Least Privilege, streamlines employee onboarding and offboarding, simplifies compliance with regulatory requirements, and scales easily as business needs evolve. Relying heavily on Profile-based permissions can make these objectives more difficult to achieve, especially in complex Salesforce environments.
A Permission Set based architecture addresses these challenges by separating user identity from business permissions, enabling administrators to assign only the access required for each role. This results in a more flexible, secure, and maintainable security model that reduces administrative overhead while improving compliance and operational efficiency. Although Salesforce has extended the timeline, organizations that continue modernizing their access management strategy today will be better positioned to adapt to future platform enhancements and evolving business requirements.
Business Case Solution
Rather than viewing Salesforce’s decision as a reason to postpone modernization, organizations should treat it as an opportunity to strengthen their security strategy on their own timeline. By gradually transitioning to a Permission Set–driven access model, businesses can reduce security risks, simplify administration, and build a scalable framework that supports future Salesforce enhancements. A structured, phased approach enables organizations to improve governance without disrupting day-to-day operations.
Phase 1: Assess Your Current Security Model
The first step is to evaluate the existing Salesforce security landscape. Organizations should review current Profiles, Permission Sets, duplicate or overlapping permissions, users with elevated privileges, and administrative access. This assessment helps identify security gaps, unnecessary access, and areas where permissions can be consolidated. Establishing a clear baseline allows businesses to prioritize improvements and develop a well-defined migration strategy.
Phase 2: Adopt a Minimum Access Profile
Organizations should redefine Profiles to provide only the minimum baseline settings required for users, while assigning business-specific permissions through Permission Sets. This approach follows the Principle of Least Privilege by ensuring users receive only the access necessary to perform their responsibilities. As a result, businesses benefit from a cleaner security model, simplified user management, reduced risk of excessive permissions, and greater consistency across user roles.

Phase 3: Standardize Permission Sets
Instead of creating numerous custom Profiles for every department or job function, organizations should develop standardized Permission Sets aligned with business roles such as Sales Representatives, Sales Managers, Service Agents, Marketing Users, Finance Teams, and System Administrators. Standardizing Permission Sets improves consistency across the organization, accelerates employee onboarding, simplifies role changes, and reduces the administrative effort required to manage user access.
Phase 4: Leverage Permission Set Groups
As organizations adopt multiple Permission Sets, managing them individually can become complex. Permission Set Groups allow administrators to bundle related permissions into reusable collections based on specific job functions or responsibilities. This makes user provisioning more efficient, simplifies ongoing maintenance, enables faster role transitions, and reduces the likelihood of configuration errors while improving overall governance.
Phase 5: Establish Regular Access Reviews
User access management should be treated as an ongoing governance process rather than a one-time implementation. Organizations should conduct periodic access reviews to remove unused or unnecessary permissions, validate that users have appropriate levels of access, identify excessive privileges, and ensure compliance with internal security policies and industry regulations. Regular reviews help maintain a secure Salesforce environment while supporting evolving business requirements.
The Business Outcome
By following this phased approach, organizations can modernize their Salesforce security model without the pressure of a mandatory migration deadline. A Permission Set–driven architecture provides stronger governance, improved operational efficiency, simplified compliance, and a scalable foundation that supports future Salesforce innovations. Instead of reacting to platform changes, businesses can proactively build a secure and flexible access management strategy that delivers long-term value.
Business Benefits
Organizations that adopt a Permission Set–first approach gain far more than improved user access management they establish a stronger foundation for long-term security, governance, and operational efficiency. By separating business permissions from Profiles, administrators can manage user access with greater flexibility while reducing complexity across the Salesforce environment.
Key business benefits include:
- Enhanced Security: Grant users only the permissions they need, reducing the risk of unauthorized access and accidental data exposure.
- Simplified Administration: Standardized Permission Sets make it easier to provision users, troubleshoot access issues, and manage role changes.
- Improved Operational Efficiency: Faster onboarding, offboarding, and user provisioning reduce administrative effort and improve employee productivity.
- Stronger Compliance and Governance: A Permission Set–driven model supports the Principle of Least Privilege, making audits, compliance reporting, and access reviews significantly easier.
- Greater Scalability: As the organization grows, new users, departments, and business processes can be accommodated without creating numerous custom Profiles.
- Future-Ready Architecture: Aligning with Salesforce’s recommended security model prepares organizations to adopt future platform enhancements with minimal disruption.
Why Clients Should Act Now
Although Salesforce has removed the mandatory retirement deadline for Profile-based permissions, its long-term security strategy remains unchanged. Permission Sets and Permission Set Groups continue to be the recommended approach for managing user access, and future platform innovations are expected to build upon this modern security framework.
Waiting until another deadline is announced may result in rushed implementations, increased project costs, and unnecessary business disruption. By taking a phased approach today, organizations can modernize their security model at a comfortable pace, spread implementation efforts over time, and reduce operational risk while continuing to support business growth.
Modernization should not be driven by deadlines it should be driven by business value, improved governance, and long-term scalability.
Our Recommendation
Organizations should use this extended timeline as an opportunity to strengthen their Salesforce security strategy rather than delaying modernization. We recommend adopting a phased transition that aligns with Salesforce’s best practices while minimizing disruption to daily operations.
Our recommendations include:
- Continue using Profiles only for baseline user settings such as login policies, default applications, and record type assignments.
- Manage business permissions through Permission Sets to provide users with role-based access that is easier to maintain and audit.
- Consolidate related permissions using Permission Set Groups to simplify administration and improve consistency.
- Follow the Principle of Least Privilege, ensuring users receive only the permissions necessary to perform their responsibilities.
- Schedule regular security and access reviews to remove unnecessary permissions and maintain compliance.
- Establish a scalable governance framework that supports future Salesforce releases and evolving business requirements.
Final Thoughts
Salesforce’s decision to postpone the retirement of Profile-based permissions provides organizations with valuable flexibility, but it should not be interpreted as a shift away from modern security practices. Instead, it offers businesses the opportunity to plan and execute their transition to a more efficient access management model without the pressure of an immediate deadline.
Organizations that embrace a Permission Set–driven architecture today will be better positioned to strengthen security, simplify administration, improve compliance, and scale their Salesforce environments as business needs evolve. Rather than reacting to future platform changes, they can proactively build a governance model that supports both current operations and long-term digital transformation.
The timeline may have changed, but Salesforce’s strategic direction remains the same. Organizations that modernize their user access model today will be better equipped to protect their data, reduce administrative complexity, and maximize the value of their Salesforce investment for years to come.


