IT CanvassTalk to an advisor
Connectors · LessonBy , SailPoint Trainer, 7 yrs · Published · IdentityIQ 8.4 · all levels

Salesforce

Governing Salesforce profiles, permission sets and licenses.

Quick answer

SailPoint uses the Salesforce API to aggregate users, profiles and permission sets and provision changes.

Key takeaways
  • Salesforce connector type: a REST/API-based connector
  • Onboarding: aggregate then correlate
  • SailPoint can create/deactivate Salesforce users and manage profiles and permission sets.
  • Common issues covered in troubleshooting

Salesforce is often a crown-jewel SaaS application holding sensitive customer and commercial data, so governing who has access, and at what profile and permission-set level, matters. SailPoint aggregates Salesforce users and their access and provisions changes through the lifecycle.

Connector type and how it connects

The Salesforce integration is a REST/API-based connector. It uses the Salesforce API authenticated with OAuth. As with every connector, the flow is the same: authenticate to Salesforce, read accounts and entitlements during aggregation, and write changes during provisioning.

Onboarding the source

  • 1. Configure the connection and credentials for Salesforce.
  • 2. Map the account schema, mapping Salesforce users, profiles, permission sets and (where relevant) license types to SailPoint accounts and entitlements.
  • 3. Set the correlation logic so Salesforce accounts attach to the right identities (typically on a stable key such as employee ID or email).
  • 4. Run account aggregation and confirm accounts and entitlements load.
  • 5. Verify correlation, watching for uncorrelated/orphan accounts.

Provisioning capabilities

SailPoint can create and deactivate Salesforce users and manage profiles and permission-set assignments, driven by roles, requests and lifecycle events. Deactivation on leaver is especially valuable given per-user licensing costs.

Entitlements and what to govern

Govern profiles and permission sets, which together determine what a Salesforce user can see and do. Note that profiles are broad and permission sets additive; certify both.

Troubleshooting

When Salesforce aggregation or provisioning fails, work through the usual causes in order:

  • Confirm the OAuth connected-app credentials are valid.
  • Verify the integration user has admin rights for user and permission management.
  • Check API access and any IP restrictions on the Salesforce org.
  • Validate profile/permission-set schema mapping.

Common pitfalls

  • Credential expiry (tokens/secrets) silently breaking the connector.
  • Insufficient rights on the Salesforce service account for the operations you need.
  • Schema or correlation misconfiguration leaving accounts uncorrelated.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
What type of connector is Salesforce?

Frequently asked questions

What does the term Salesforce connector refer to in SailPoint?
Salesforce is often a crown-jewel SaaS application holding sensitive customer and commercial data, so governing who has access, and at what profile and permission-set level, matters. SailPoint aggregates Salesforce users and their access and provisions changes through the lifecycle.
What is worth remembering about Salesforce connector in practice?
The Salesforce integration is a REST/API-based connector. It uses the Salesforce API authenticated with OAuth.
What is another point to note about Salesforce connector?
As with every connector, the flow is the same: authenticate to Salesforce, read accounts and entitlements during aggregation, and write changes during provisioning.
What tends to go wrong with Salesforce connector?
Credential expiry (tokens/secrets) silently breaking the connector. Insufficient rights on the Salesforce service account for the operations you need. Schema or correlation misconfiguration leaving accounts uncorrelated.
Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support