Every Salesforce release comes with exciting new features. Winter ’27 is no exception. But before you start experimenting with new AI, automation, and revenue capabilities, there are a few less glamorous updates that deserve attention first.
This release includes several security and integration changes that can create real disruption if they are left until the last minute.
Connected Apps Are on the Clock
Salesforce is continuing its shift from Connected Apps to External Client Apps. Beginning in Winter ’27, customers can start migrating packaged and distributed Connected Apps, and Salesforce plans to end support for Connected Apps in Summer ’27.
Connected Apps will not suddenly stop working when support ends, but Salesforce says it will no longer provide bug fixes or support for the integrations and authorization flows that depend on them. That makes Winter ’27 a good time to inventory what is connected to your org and build a migration plan rather than waiting for a production issue to force the conversation.
Older OAuth Flows Need Attention Too
Salesforce has also set February 20, 2027 as the enforcement date for retiring the OAuth 2.0 username-password flow for Connected Apps. Integrations that still rely on that flow will break unless they are updated. Salesforce recommends moving to more secure approaches such as the web-server flow with PKCE or client credentials flow, depending on the use case.
User-agent and hybrid user-agent OAuth flows are also being retired, while API traffic using incorrect instanced URLs is another area organizations should review.
None of these changes are especially flashy. That is exactly why they are easy to overlook.
What Should You Do Now?
Start with an integration inventory. Identify Connected Apps, authentication methods, integration users, API endpoints, and any older middleware or custom applications that have been quietly running for years.
Then test the changes in a sandbox, document dependencies, and prioritize integrations based on business impact. A small integration that moves a nightly file is very different from one supporting order capture, customer service, or billing.
Winter ’27 is a good reminder that release readiness is not only about turning on new features. Sometimes the most important work is making sure the technology you already depend on keeps working.
Palladin can help assess your Salesforce integrations, identify areas affected by upcoming security changes, and create a migration and testing plan that reduces risk before enforcement dates arrive.