Salesforce Dictionary - Free Salesforce GlossarySalesforce Dictionary
DictionaryHHealth Check
AdministrationBeginner

Health Check

Health Check is a Setup tool that evaluates the security configuration of the Salesforce org against Salesforce's recommended baseline standards.

§ 01

Definition

Health Check is a Setup tool that evaluates the security configuration of the Salesforce org against Salesforce's recommended baseline standards. It assigns a score from 0 to 100 and identifies specific settings that are below recommendations, such as password policies, session settings, and login requirements.

§ 02

In plain English

👋 Study buddy

Here's a simple way to think about it: Health Check turns "is our org secure?" from opinion into a score. Salesforce evaluates dozens of security settings against a baseline and returns a number you can act on - a 70 means specific things, and the page tells you exactly what to change.

§ 03

Worked example

scenario · real-world use

The admin at Granite Financial runs Health Check and receives a score of 72 out of 100. The tool flags that the minimum password length is only 8 characters (recommendation: 12), session timeout is set to 12 hours (recommendation: 2 hours), and clickjack protection is disabled. She updates each setting and reruns Health Check, achieving a score of 95.

§ 04

Why Health Check turns "is our org secure?" from opinion into score

"Is our org secure?" is impossible to answer in the abstract. Health Check is Salesforce's attempt to make it answerable in the concrete. The tool evaluates dozens of security-relevant settings - password policies, session timeouts, login IP ranges, certificate expirations - against Salesforce's recommended baseline (or a custom baseline you define) and produces a single score with line-item findings. A 70 means specific things; the page tells you exactly what to change to reach 80.

The reason it's most useful as a recurring discipline rather than a one-time check is that the underlying settings drift. Someone widens an IP range for a vendor and forgets to narrow it back; password policy is reset during a sandbox refresh; a certificate ages closer to expiration. Run Health Check monthly, share the score with the security stakeholder, and treat declines as small fires worth investigating rather than waiting for the score to drop dramatically.

§ 05

How to set up Health Check

Health Check is Salesforce's built-in security audit dashboard — it scores your org against the Salesforce Baseline Standard (or a custom baseline you upload) and flags settings that fall short. You don't "set up" Health Check; you run it, then fix the actual underlying settings it flags.

  1. Open Setup → Health Check

    Setup gear → Quick Find: Health Check → Health Check.

  2. Review the score against the Salesforce Baseline Standard

    Score is 0-100. Anything under 80 means meaningful gaps. The dashboard groups findings by High / Medium / Low / Informational risk.

  3. Drill into a finding to see the gap

    Each finding shows your current value vs the baseline value. The Edit button takes you straight to the Setup page that controls it.

  4. Adjust the underlying setting

    Health Check is read-only — you fix Session Settings, Password Policies, Sharing Settings, etc. on their own pages, then Health Check picks up the new value.

  5. (Optional) Upload a Custom Baseline

    Setup → Health Check → Custom Baselines tab → Upload XML. Lets you define your own thresholds when industry compliance differs from Salesforce defaults.

  6. Re-run Health Check

    Live dashboard — values update on next page load. Good practice to run it monthly or after major Setup changes.

Key options
Salesforce Baseline Standardremember

The default baseline. Reflects Salesforce's current security recommendations.

Custom Baseline (XML)remember

Upload your own thresholds. Useful for FedRAMP, HIPAA, or other compliance regimes.

Risk Categoriesremember

High Risk findings should be addressed first; Medium should be planned; Low and Informational are best-effort.

Gotchas
  • Health Check is read-only. The Edit button on each finding takes you to the underlying Setup page — fix the actual setting there, not in Health Check.
  • Custom Baselines override the Salesforce Baseline Standard for the categories you define. Findings outside your custom baseline still use Salesforce defaults — this is intentional.
  • Score moves slowly. Fixing one High Risk finding can move you from 65 to 78. Don't expect linear progress — some findings are weighted heavily.
§ 06

How organizations use Health Check

Pacific Crest Bank

Monthly Health Check became the security team's lead indicator; sustained score declines surface architectural drift before it becomes incidents.

BlueRiver Health

Compliance team uses Health Check as audit evidence; the score and findings are reproducible and dated.

Atlas Manufacturing

Quarterly Health Check baseline reviews caught a vendor's IP-range request that had widened login access; the team narrowed it back.

§

Trust & references

Official documentation

Straight from the source - Salesforce's reference material on Health Check.

Was this entry helpful?
Help us write better definitions. Quick reactions or detailed edit suggestions.
§

Test your knowledge

Q1. Why is understanding Health Check important for Salesforce admins?

Q2. In which area of Salesforce would you typically find Health Check?

Q3. What is the primary benefit of Health Check for Salesforce administrators?

§

Discussion

Loading…

Loading discussion…