Microsoft Defender for Cloud Apps
Cloud and workloads

Protect your Salesforce environment | Microsoft Defender for Cloud Apps

In brief

The documentation now distinguishes Salesforce Shield requirements for SSPM versus other integrations, and adds Salesforce and Event Manager setup steps before connecting Defender for Cloud Apps.

What Defender admins need to know

Administrators must complete the required Salesforce setup and enable the required events before connecting. Salesforce Shield is not required for SSPM integrations.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

As a major CRM cloud provider, Salesforce incorporates large amounts of sensitive information about customers, pricing playbooks, and major deals inside your organization. Being a business-critical app, people inside your organization and others outside of it (such as partners and contractors) access and use Salesforce for various purposes. In many cases, a large proportion of your users accessing Salesforce have low awareness of security and might put your sensitive information at risk by unintentionally sharing it. In other instances, malicious actors might gain access to your most sensitive customer-related assets.

Connecting Salesforce to Defender for Cloud Apps gives you improved insights into your users' activities, provides threat detection using machine learning based anomaly detections and information protection detections (such as detecting external information sharing). Defender for Cloud Apps also enables automated remediation controls, and detects threats from enabled third-party apps in your organization. Before you begin, review the prerequisites for connecting Salesforce to Defender for Cloud Apps.

[!INCLUDE security-posture-management-connector]

Main threats to your Salesforce environment

Connecting Salesforce to Defender for Cloud Apps helps you detect and respond to these key threats:

  • Compromised accounts and insider threats
  • Data leakage
  • Elevated privileges
  • Ransomware
  • Unmanaged bring your own device (BYOD)

Prerequisites

Before you connect Salesforce to Defender for Cloud Apps, complete the following prerequisites:

  • Install and authorize the Salesforce Connected App in the target Salesforce org before you start the connection process. Salesforce enforces usage restrictions on Connected Apps. For more information, see:Prepare for Connected App Usage Restrictions Change

  • Assign the Approve Uninstalled Connected Apps permission to the Salesforce service account used to connect Microsoft Defender for Cloud Apps. Salesforce requires this permission to connect third-party apps via OAuth.

How Defender for Cloud Apps helps to protect your environment

Defender for Cloud Apps helps protect your Salesforce environment in the following ways:

SaaS security posture management for Salesforce

Connect SalesforceConnect Salesforce to Microsoft Defender for Cloud Apps to automatically get security recommendations for Salesforce in Microsoft Secure Score. For connection steps, see Connect Salesforce to Microsoft Defender for Cloud Apps.

In Secure Score, select Recommended actions and filter by Product = Salesforce. For example, recommendations for Salesforce include:

Prerequisites

  • For all integrations other than

    SaaS security posture management (SSPM), doesn't require Salesforce Shield. For all other integrations, make sure that Salesforce Shield is available for your Salesforce instance.

Use the following instructions to connect Microsoft Defender for Cloud Apps to your existing Salesforce account using the app connector API. The Salesforce app connector gives you visibility into and control over Salesforce use.

Configure Salesforce

Perform the following steps in Salesforce before connecting the app:

  1. In your Salesforce account, create a dedicated service admin account for Defender for Cloud Apps.

  2. Create a new profile for the Defender for Cloud Apps service account. Use this profile to configure the App connector.

  3. Make sure that the service account profile includes the following permissions:

  4. In the next window, enter a name for the connection and select Next.

  5. In Follow the link, select Connect Salesforce.

  6. This actionSelecting Connect Salesforce opens the Salesforce sign sign-in page. Enter your credentials to allow Defender for Cloud Apps access to your team's Salesforce app.

    :::image type="content" source="media/salesforce-logon.png" alt-text="Screenshot that shows a pop-up and how to enter your Salesforce credentials." lightbox="media/salesforce-logon.png":::

Enable the events in Salesforce Event Manager

Perform the following steps in Salesforce Event Manager to enable the required events:

  1. Sign in to Salesforce as an administrator.
  2. Go to https://YOURDOMAIN.lightning.force.com/lightning/setup/EventManager/home.
  3. Search for each of the following events and enable Storing data:

Next steps