Skip to content
IT Canvass
Connectors · Lesson

Salesforce

Quick answer

SailPoint uses the Salesforce API to aggregate users, profiles and permission sets and provision changes.

Key takeaways

  • Salesforce connector type: a REST/API-based connector
  • Onboarding: aggregate then correlate
  • SailPoint can create/deactivate Salesforce users and manage profiles and permission sets.
  • Common issues covered in troubleshooting

Salesforce is often a crown-jewel SaaS application holding sensitive customer and commercial data, so governing who has access, and at what profile and permission-set level, matters. SailPoint aggregates Salesforce users and their access and provisions changes through the lifecycle.

Connector type and how it connects

The Salesforce integration is a REST/API-based connector. It uses the Salesforce API authenticated with OAuth. As with every connector, the flow is the same: authenticate to Salesforce, read accounts and entitlements during aggregation, and write changes during provisioning.

Onboarding the source

  • 1. Configure the connection and credentials for Salesforce.
  • 2. Map the account schema, mapping Salesforce users, profiles, permission sets and (where relevant) license types to SailPoint accounts and entitlements.
  • 3. Set the correlation logic so Salesforce accounts attach to the right identities (typically on a stable key such as employee ID or email).
  • 4. Run account aggregation and confirm accounts and entitlements load.
  • 5. Verify correlation, watching for uncorrelated/orphan accounts.

Provisioning capabilities

SailPoint can create and deactivate Salesforce users and manage profiles and permission-set assignments, driven by roles, requests and lifecycle events. Deactivation on leaver is especially valuable given per-user licensing costs.

Entitlements and what to govern

Govern profiles and permission sets, which together determine what a Salesforce user can see and do. Note that profiles are broad and permission sets additive; certify both.

Troubleshooting

When Salesforce aggregation or provisioning fails, work through the usual causes in order:

  • Confirm the OAuth connected-app credentials are valid.
  • Verify the integration user has admin rights for user and permission management.
  • Check API access and any IP restrictions on the Salesforce org.
  • Validate profile/permission-set schema mapping.

Common pitfalls

  • Credential expiry (tokens/secrets) silently breaking the connector.
  • Insufficient rights on the Salesforce service account for the operations you need.
  • Schema or correlation misconfiguration leaving accounts uncorrelated.

Want to learn this properly?

Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.

Check your understanding

  1. What type of connector is Salesforce?

    • A. Configure the connection and credentials, then aggregate accounts and correlate them to identities.
    • B. a REST/API-based connector. It uses the Salesforce API with OAuth.
    • C. Credentials, network/firewall access and schema mapping.
    Show answer

    B. a REST/API-based connector. It uses the Salesforce API with OAuth.

    a REST/API-based connector. It uses the Salesforce API with OAuth.

  2. What is the first onboarding step for Salesforce?

    • A. a REST/API-based connector. It uses the Salesforce API with OAuth.
    • B. Configure the connection and credentials, then aggregate accounts and correlate them to identities.
    • C. Credentials, network/firewall access and schema mapping.
    Show answer

    B. Configure the connection and credentials, then aggregate accounts and correlate them to identities.

    Configure the connection and credentials, then aggregate accounts and correlate them to identities.

  3. Where do most Salesforce connector issues come from?

    • A. a REST/API-based connector. It uses the Salesforce API with OAuth.
    • B. Configure the connection and credentials, then aggregate accounts and correlate them to identities.
    • C. Credentials, network/firewall access and schema mapping.
    Show answer

    C. Credentials, network/firewall access and schema mapping.

    Credentials, network/firewall access and schema mapping.

Frequently asked questions

What does the term Salesforce connector refer to in SailPoint?

Salesforce is often a crown-jewel SaaS application holding sensitive customer and commercial data, so governing who has access, and at what profile and permission-set level, matters. SailPoint aggregates Salesforce users and their access and provisions changes through the lifecycle.

What is worth remembering about Salesforce connector in practice?

The Salesforce integration is a REST/API-based connector. It uses the Salesforce API authenticated with OAuth.

What is another point to note about Salesforce connector?

As with every connector, the flow is the same: authenticate to Salesforce, read accounts and entitlements during aggregation, and write changes during provisioning.

What tends to go wrong with Salesforce connector?

Credential expiry (tokens/secrets) silently breaking the connector. Insufficient rights on the Salesforce service account for the operations you need. Schema or correlation misconfiguration leaving accounts uncorrelated.
CallWhatsAppEnquire