The benefits of upgrading to FileMaker 16: Security Enhancements

Ben Fletcher • May 15, 2017

Security considerations have always been a priority when building a Custom App, but now we are in the 'cloud-age' it is even more critical to get it right from the outset and to periodically audit. Recent events in the UK such as the NHS ransomware cyber-attack only brings this into sharper focus.

FileMaker 16 has further improved on an already strong set of security features in FileMaker 15 with a number of important enhancements:



HTTP Strict Transport Security (HSTS) optional setting requires that web-client connections use SSL encryption. Although SSL for database connections has long been a part of FileMaker Server this new setting forces web clients (e.g. WebDirect users) to access your FileMaker data over HTTPS connections. Once the web client has completed an HTTPS connection, the web browser prevents the user from downgrading to HTTP connections. This new option is recommended as a simple belt and braces measure.

OAuth 2.0 support for accounts allows you to integrate external authentication providers within your eco system right within the FM platform. This supports Amazon, Microsoft Azure & Google and is controlled by FileMaker Server. If your server has all 3 configured and enabled you will see all 3 icons on your FileMaker Pro login dialog. Single sign on authentication is a popular modern feature that FileMaker have adopted for your convenience.

• Clickable security lock icons. FileMaker Pro has for long indicated the security of your connection to a FileMaker Server via a range of padlock icons. A single click on the padlock icon now provides more details about the security of your connection e.g. certificate details and validity or suggestions for an insecure connection.

Field-level text encryption Is an extra layer of protection for your data. It enhances the already existing comprehensive access restrictions that can be found in the manage security dialog where you can limit access to tables,layouts and fields by privilege set. The new encryption functions can be built into a solution’s logic in order to easily and securely encrypt text or container fields containing sensitive data. Then you can program to either a) allow users access to the decrypted field data when they enter the correct password or b) program your chosen conditions (e.g. specific users) under which to decrypt and display the previously encrypted field data.

There are 3 new extended privileges to lock down access to external interactions with your FileMaker data by privilege set. ‘fmrest’ determines whether members of a privilege set can access the database file from a web service via the new FileMaker Data API available with FileMaker Server. ‘fmurlscript’ determines whether members of a privilege set can run FileMaker scripts from URLs; called using the FMP URL protocol. ‘fmextscriptaccess’ determines whether members of a privilege set can use external applications such as Apple events and ActiveX to control your FileMaker app. If a user’s privilege set does not have the privilege enabled for one of these actions that they perform, they will see the standard FileMaker error; ‘Your access privileges do not allow you to perform this operation’.


Even with the additional security enhancements of the FileMaker 16 platform, it can be an intimidating process to lock down your Custom App if you are new to the FileMaker platform so if you are not sure where to start you can always contact our consulting Team for a security audit.


by Ben Fletcher 17 Nov, 2023
New Features in Claris FileMaker 2023 (version 20.3) Release
by Ben Fletcher 08 Sept, 2023
Reflecting on Claris Platform's Roadmap: What's Next in 2023 and Beyond
by Ben Fletcher 06 Jun, 2023
The Claris FileMaker 2023 is the ultimate platform for custom app creation. Given its advanced features and capabilities, it's the platform of choice for those seeking to start fresh building a new custom business app. However, if you're thinking about upgrading from an older Claris FileMaker version, preparation is key, and that's where we come in . . .
by Ben Fletcher 27 Apr, 2023
New Features in Claris FileMaker 2023 Release
by Ben Fletcher 01 Feb, 2023
Free tier access to the Claris Platform is coming!
by Ben Fletcher 01 Dec, 2022
New Features in Claris FileMaker 19.6 Release
by Ben Fletcher 28 Nov, 2022
Claris Server managed private cloud hosting now available from datatherapy.host
by Ben Fletcher 24 Nov, 2022
The new Claris Platform represents the latest evolution of the venerable Claris FileMaker Platform. While the FileMaker Platform is a powerful and flexible toolset, it was originally launched in 1985 and conceived to solve the data problems of that era - predating much of the modern internet staples that we are familiar with today like pervasive broadband, mobile computing and cloud services. While an impressive number of new features have been added to the FileMaker platform to modernise it over the years, there were always going to be some areas where it was not an optimal solution given the need to maintain compatibility with previous releases. The new Claris Platform focuses on offering a new approach to building unified, hybrid apps with a more cloud native approach. Central to this new offering is Claris Studio, a web-based tool for building online web forms, dynamic charts, dashboards and task trackers (see https://www.claris.com/studio/ ). Historically, these are all areas that the FileMaker platform has served poorly out of the box, or has required substantial developer effort utilising 3rd party plugins or integration with other apps and cloud services to work around. The new Claris Platform bundle therefore significantly extents what would be possible with FileMaker alone. I t is well worth looking at these Claris Youtube videos exploring the new platform https://youtube.com/playlist?list=PLkvKnBkQSCeTE1hT4FJkCJ_foOOq_DBIe However, Claris Studio does not integrate with classic FileMaker Pro and FileMaker Server - instead it works with Claris Pro and Claris Server. In order to get Claris Studio to market and in the hands of developers as quickly as possible, Claris have had to make some compromises and so narrowed their initial platform support and features. This means that while Claris Pro and Claris Server have most of the core features of FileMaker Pro and FileMaker Server there are some important differences - while the new Claris platform is an excellent fit for most new development projects, it is not yet a 'no-brainer' upgrade for existing FileMaker customers that are reliant on some of the older features which are not yet present in the new platform. Two deciding limitations for many existing FileMaker customers are that: 1) Claris Server only currently runs on the Linux platform - there is no support for running on macOS or Windows servers currently. 2) By design the new Claris Platform needs internet access in order to integrate with Claris Studio and so cannot be 'LAN locked' which may be the case for certain FileMaker solutions due to strict security as can be found in healthcare environments or with very high performance solutions such as video environments. If you don't have expertise in deploying Linux servers or moving from a LAN to cloud environment then this can be mitigated as it is perfectly possible to get a 3rd party managed private cloud hosting. This is exactly the service that DataTherapy can provide - see https://datatherapy.host/pricing for more details. Contact our team if you are interested in a demo of the new Claris Platform offering and a FREE initial consultation about how to migrate from from your existing FileMaker based solution in order to take advantage of the new Claris Studio features.
by Ben Fletcher 16 Jun, 2022
New Features in Claris FileMaker 19.5 Release
by Ben Fletcher 17 Dec, 2021
We can confirm that our Platopus platform does not make use of Java and so is unaffected by the Log4j security vulnerability.
More posts
Share by: