Salesforce cancels the profile permission retirement
Salesforce has officially rescinded its plan to retire permissions from Profiles. The retirement was originally slated for Spring '26 and is now indefinitely postponed. The decision answers customer feedback and feature gaps, and it changes nothing about how permissions should be managed: the principle of least privilege is still the recommended security model, and Permission Sets are still the preferred tool for getting there.
Background: how the retirement timeline moved
Getting to this point has taken years, and for a lot of people it has been frustrating.
- January 2023: Salesforce announced the end-of-life for permissions on Profiles, targeting Spring '26. That gave the ecosystem three years to plan the transition.
- 2024: Salesforce softened its stance. The Spring '26 enforcement date would no longer be mandatory, though the recommendation for a Permission Set-led security model stood, and Profiles were slated for no new feature investment.
- The recent update: Salesforce has quietly updated its Knowledge articles to confirm the outright cancellation of the retirement plan.
Reasons for the reversal
Two things drove it. A significant portion of the customer base pushed back on the retirement, saying they were not ready. And the tooling and platform functionality were not deemed good enough to support a smooth, large-scale migration for every organization.
An SF Ben Admin Survey found that only 20.5% of organizations had fully transitioned to a Permission Set-led security model, so the readiness problem was widespread.
Implications for administrators and developers
- Roadmap uncertainty. If you prioritized the migration because of Salesforce's original timeline, this shift is disruptive. Development roadmaps and other initiatives may have been shaped around an assumption that has now changed.
- Permission Sets still matter. The recommendation to adopt a Permission Set-led model for least privilege still holds, and the work already done in that direction is not wasted.
- Security practice does not depend on the roadmap. Least privilege is a fundamental security practice whatever Salesforce announces, and permissions need managing proactively either way.
- Feature gaps and workarounds. Record Type access and App Defaults have historically been awkward when migrating from Profiles to Permission Sets. Many capabilities are unified now, but those specific gaps may be part of what caused the delay, and they still need thinking through.
What admins and developers should do now
Cancelling the retirement does not change the security objectives behind it.
- Review your current permission model. Look at how permissions are actually distributed today, and where that differs from good practice.
- Prioritize least privilege. Keep using Permission Sets and Permission Set Groups to grant only the access someone needs. That model is easier to secure and easier to maintain.
- Address the remaining feature gaps. If you still depend on Profiles for things Permission Sets do not fully replicate, such as certain Page Layout configurations or Record Type access, find the most scalable workaround available.
- Keep at it. Security is ongoing work, and a cancelled retirement is not a reason to let permissions drift.
Leave a Comment