Cisco Secure Access Help

PDF

Cisco Secure Access Help

Enable Cloud Malware Protection for Salesforce Tenants

Want to summarize with AI?

Log in

Provides instructions for completing the Enable Cloud Malware Protection for Salesforce Tenants workflow in Cisco Secure Access. You must have full admin access to the Secure Access dashboard.


Secure Access supports Cloud Malware protection in both production and sandbox development Salesforce environments for:

  • files uploaded to your Salesforce Enterprise Grid deployment in the Sales Cloud and Service Cloud.

  • files exchanged in Salesforce chatter posts. (Cloud Malware protection is not available for Salesforce sObjects or chatter posts--only for files attached to chatter posts.)

To enable this protection you must first authorize your Salesforce tenant with Secure Access as described here.

Before you begin

The Salesforce user account to which the quarantine package is deployed and permissions are applied must be the same one that will be used to authorize the Salesforce tenant for Cloud Malware protection

Procedure

  1. Navigate to Admin > Authentication.

  2. Under SaaS API Platforms, click to expand Salesforce.

    The Authorize Salesforce Malware interface.
  3. In the Cloud Malware section, click Authorize New Tenant to add a Salesforce tenant to your Secure Access environment.

  4. In the Salesforce Authorization dialog, click the Salesforce Quarantine Package link and deploy the Salesforce quarantine package to your Salesforce tenant. This enables Secure Access to support the quarantine response action for Salesforce. (If you have already deployed the package to support SaaS API DLP for this tenant, you need not do it again.)

    The Malware Quarantine Package Link interface.
  5. In the Salesforce Authorization dialog, check the checkboxes to verify you meet the prerequisites, then click Next.

  6. Enter the Tenant Name. If the tenant is a Salesforce sandbox, check Salesforce Sandbox. Click Next.

    The Salesforce Malware Tenant Name interface.
  7. Select a Response Action for Secure Access to apply to Salesforce files found with malware and then click Next.

    • Choose Monitor to cause Secure Access to log Salesforce files detected with malware (including those attached to chatter posts). You will be able to manually quarantine files from the Cloud Malware report.

    • Secure Access applies the Quarantine response action to files only (including those attached to chatter posts). The quarantine option will work for Salesforce only if you have downloaded the Salesforce quarantine package and installed it for your Salesforce tenant. Choose Quarantine to:

      • Remove all collaborators, and change the file owner to the Salesforce admin who has performed the authorization, and who has been assigned the permisson set for the quarantine app. In Salesforce, the admin can see a list of quarantined files by using the App Launcher to search for "Cisco Secure Access SF Quarantine," then selecting the All Quarantines option.

        The Sfapp Launcher All Quarantines interface.

        Click on the listing for an individual file to see the information about it:

        The Sfquarantined File interface.
      • Replace the file in its original location with a text file named filename_Cisco_Quarantined.txt explaining to the original file owner that the file is identified as malware and for more information to contact their organization administrator.

    The Salesforce Response Action Malware interface.
  8. Click Next to be redirected to the Salesforce login page.

    The Salesforce Integration Malware interface.
  9. Log in to Salesforce with admin credentials to grant access.

    The Salesforce Login Page interface.

    You are redirected to Secure Access and a message appears showing the integration was successful. It may be up to 24 hours for the integration to be confirmed and appear as Authorized.

  10. Click Done to complete.

    The Salesforce Malware Auth Success interface.
  11. The new tenant will appear on the Authorization page in the list under Salesforce.

    If you checked Salesforce Sandbox in Step 6, the tenant name will have [Sandbox] appended to it.

    The Salesforce Malware New Tenant interface.

Edit a Salesforce Cloud Malware Tenant

You can change the Response Action you have selected for a Salesforce tenant. Secure Access supports Cloud Malware protection for files uploaded to your Salesforce Enterprise Grid deployment or exchanged in Salesforce chatter posts--in both production and sandbox development environments. (Cloud Malware protection is not available for Salesforce sObjects or chatter posts--only for files attached to chatter posts.)

Before you begin

  • You must have the Secure Access Full Admin user roll. For more information, see Manage Accounts.

Procedure

  1. Navigate to Admin > Authentication.

  2. In the SaaS API Platforms section, click Salesforce.

  3. In the Cloud Malware section , from the Edit column, click Edit. You can edit any tenant.

    The Edit Malware Tenant interface.
  4. Select a Response Action for Secure Access to apply to Salesforce files found with malware and then click Next.

    The Salesforce Malware Response Action Edit interface.
    • Choose Monitor to cause Secure Access to log files detected with malware. You will be able to manually quarantine these files from the Cloud Malware report.

    • Secure Access applies the Quarantine response action to files only. The quarantine option will work for Salesforce only if you have downloaded the Salesforce quarantine package and installed it for your Salesforce tenant. When the system quarantines a Salesforce file:

      • The system remove all collaborators, and changes the file owner to the Salesforce admin who has performed the authorization, and who has been assigned the permisson set for the quarantine app. In Salesforce, the admin can see a list of quarantined files by using the App Launcher to search for "Cisco Secure Access SF Quarantine," then selecting the All Quarantines option.

        The Sfapp Launcher All Quarantines interface.

        Click on the listing for an individual file to see the information about it:

        The Sfquarantined File interface.
      • The system replaces the file in its original location with a text file named filename_Cisco_Quarantined.txt explaining to the original file owner that the file is identified as malware and for more information to contact their organization administrator.

  5. Click Next.

    The Edit Malware Tenant Final Step interface.

    The new Response Action is displayed.

    The Edit Malware Tenant Result interface.