Cisco Secure Access Help

PDF

Cisco Secure Access Help

Requirements for Salesforce Tenants for Cloud Malware and SaaS API DLP

Want to summarize with AI?

Log in

Describes Requirements for Salesforce Tenants for Cloud Malware and SaaS API DLP in Cisco Secure Access. To support Cloud Malware protection or SaaS API Data Loss Prevention for Salesforce tenants, you must meet the requirements listed below.


To support Cloud Malware protection or SaaS API Data Loss Prevention for Salesforce tenants, you must meet the requirements listed below. All of these requirements are referenced from the appropriate topics for authorizing your Salesforce tenants for Cloud Malware protection or SaaS API Data Loss Prevention; they are gathered together here for convenience.

All of these prerequisite activities need be performed only once for any tenant; if you want to support both Cloud Malware and SaaS API DLP for a tenant, you need not do these things twice for that tenant.

The Salesforce user account to which the which the quarantine package is deployed and permissions are applied must be the same one that will be used to authorize the Salesforce tenant for Cloud Malware Protection and/or SaaS API Data Loss Prevention.


Salesforce sObjects Supported for SaaS API DLP

Secure Access SaaS API DLP supports monitoring:

  • the core sObjects listed in the table below.

  • any custom sObject that is queryable and has a text field associated with it.

Secure Access supports only the monitor response action (not quarantine) for Salesforce sObjects.

Access Document Entity Map Platform Cache Partition Type
Access Share Duplicate Record Item Predefined Case Team
Account Duplicate Record Set Predefined Case Team Member
Account Contact Role Email Domain Key Predefined Case Team Record
Account Share Email Message Price Book
Action Link Group Template Email Service Price Book Entry
Action Link Template Email Services Address Product
Additional Directory Number Email Template Profile
Announcement Endorsement Push Topic
Apex Class Endorsement Feed Queue Sobject
Apex Debug Log Entity Subscription Quick Text
Apex Email Notification Event Quick Text Share
Apex Test Queue Item Event Relation Recently Viewed
Apex Trigger External Data User Authentication Record
AppMenuItem Feed Comment Record Type
Approval Request Feed Item Role
Asset Field Permissions Setup Entity Access
Attachment Flow Interview Skill
Aura Component Bundle Flow Interview Share Skill Feed
Auth Session Folder Skill Share
Auth. Provider Forecasting Share Skill User
Badge Goal Skill User Feed
Badge Feed Goal Share Social Persona
Badge Received Group Social Post
Badge Share Group Member Social Post Feed
Business Hours Group Member Request Social Post Share
Business Process Group Record Solution
CORS Whitelist Origin Holiday Static Resource
Call Center Idea Streaming Channel
Campaign Lead Streaming Channel Share
Campaign Member Letterhead Task
Campaign Member Status Library Document Tenant Secret
Case Lightning Component Definition Thanks
Case Comment List View Chart Thanks Share
Case Contact Role Login IP Topic
Case Solution Macro Topic Feed
Case Team Member Macro Instruction Trial Template
Case Team Member Role Macro Share TxPolicyGroup
Category Data Mail Merge Template TxPolicyMember
Category Node Note User
Chatter invitation Object Permissions User List View
Client Browser Opportunity User List View Criteria
Contact Opportunity Contact Role User Login
Content Delivery Opportunity Product User Package License
Content Document Opportunity Share User Provisioning Account
Content Document Link Opportunity: Competitor User Provisioning Account Staging
Content Folder Order User Provisioning Config
Content Folder Member Order Feed User Provisioning Log
Content Version Order Product User Provisioning Mock Target
Contract Order Product Feed User Provisioning Request
Contract Contact Role Organization User Provisioning Request Share
Custom Brand Organization-wide From Email Address User Share
Customer Brand Asset Partner UserAppMenuCustomization
Custom Button or Link Permission Set UserAppMenuCustomization Share
Custom S-Control Permission Set Assignment Visualforce Component
Daily Record View Permission Set License Assignment Visualforce Page
Document Platform Cache Partition

Install or Update Node.js

The Salesforce CLI requires Node.js to run.

We recommend using Node.js 18.x or higher; Node.js 20.x is preferred.

Procedure

  1. Check your current Node.js version:

    1. Open your terminal or command prompt and run node -v.
    2. If you see a version number (e.g., v18.17.0), you have Node.js installed.
      • If you have Node.js 18.x or higher , you can skip this task.

      • If the version is below 18.x , or if the command is not found, you need to install or update Node.js; proceed to Step 2.

  2. Install/update Node.js using one of two methods:

    • Using the Node Version Manager (NVM).

      This method allows you to easily switch between different Node.js versions, which can be useful if you work on multiple projects with different requirements. To install Node.js using NVM, proceed to Step 3.

    • Using the direct installer.

      This is a simple installation suitable if you expect to use a single version of Node.js. To install Node.js using the direct installer, proceed to Step 4.

  3. Install Node.js using the Node Version Manager (NVM).

    1. Install NVM using the instructions at the NVM GitHub repository:
    2. Close and reopen the terminal or command window.
    3. Run nvm install X. (Where X is the desired version number of NVM.)
    4. Run nvm use X. (Where X is the desired version number of NVM.)
    5. Run node -v to confirm you have the desired version of Node.js installed.
  4. Install Node.js using the direct installer.

    1. Go the official Node.js website.
    2. Download the "LTS" (Long Term Support) version installer for your operating system. (This is usually the most stable and recommended version.)
    3. Run the installer and follow the prompts.
    4. Close and reopen the terminal or command window.
    5. Run node -v to confirm you have the desired version of Node.js installed.

Install the Salesforce CLI

The Salesforce Command Line Interface (CLI) is the primary tool for interacting with Salesforce orgs and managing Salesforce DX projects.

Before you begin

Procedure

  1. Open a terminal or command prompt window

  2. Go to the official Salesforce CLI website.

  3. Download the appropriate installer for Windows, macOS, or Linux.

  4. Run the installer and follow the prompts.

  5. Close and reopen the terminal or command prompt window.

  6. Run sf --version to confirm you have the desired version of the Salesforce CLI installed.

You should see the installed Salesforce CLI version number. If you see an error, ensure the CLI is added to your system's PATH and try again.


Deploy the Salesforce Quarantine Package to your Salesforce Tenant

Before authorizing a Salesforce org as a tenant for Cloud Malware protection or SaaS API Data Loss Prevention you must assign the proper permissions and deploy the Salesforce quarantine package to the Salesforce admin user account that will be used to authorize the tenant. This allows the quarantine response action to function in your environment.

Note
If the Salesforce tenant authorization is revoked and then restored with a new admin user, that admin user will need the same permissions enabled and the quarantine package will need to be deployed for that user.

You need to do this only once for any Salesforce tenant; if you want to support both Cloud Malware and SaaS API DLP for a tenant, you need not do it twice for that tenant.

Before you begin

  • You must have full admin access in a Salesforce Enterprise account.

  • You must install or update Node.js. The Salesforce CLI requires Node.js to run. We recommend using Node.js 18.x or higher; Node.js 20.x is preferred.

  • You must have the Salesforce CLI installed.

The Salesforce user account to which the quarantine package is deployed must be the same one that will be used to authorize the Salesforce tenant for Cloud Malware protection and/or SaaS API Data Loss Prevention.

Procedure

  1. Upload the Salesforce qurantine package to your local device. Use the link provided in the Secure Access UI in the first step of the Salesforce authorization process for Cloud Malware protectionor the Salesforce authorization process for SaaS API Data Loss Prevention:

    The Malware Quarantine Package Link interface.

    The uploaded file is a signed .zip file.

  2. Extract or unzip the .zip file. Confirm the contents:

    • A signed QuarantineApp_x.y.z.zip file.

    • A .sig file.

    • An sha256 manifest file.

    • A python script to verify the signed package.

    • A README file describing how to use the verification script.

  3. Extract or unzip the QuarantineApp_x.y.z.zip file.

    Confirm the contents: .cls, .xml, and .json files.

  4. The extracted package is structured as a Salesforce DX project.

    • The directory must contain an sfdx-project.json file.

    • Your metadata should reside in force-app/main/default.

  5. Set your current directory to the Salesforce DX project directory.

  6. Log in to your Salesforce org.

  7. Run the deploy command:

    sf project deploy start --target-org MyTargetOrg --source-dir force-app

    Where MyTargetOrg is an alias for your authorized org.

    This command deploys all metadata from your project's default package directory (usually force-app/main/default) to the target org you specify. The CLI will display the deployment progress, including the status of components being deployed, any warnings, and errors.

  8. If you have deployed to a sandbox environment, you must run local tests to confirm successful deployment. Run the command:

    sf apex run test --target-org MyTargetOrg --test-level RunLocalTests --code-coverage --result-format human --synchronous

    Where MyTargetOrg is an alias for your authorized org.

    If an error appears, Contact Support.

  9. Return to Enable Cloud Malware Protection for Salesforce Tenants or Enable SaaS API Data Loss Prevention for Salesforce Tenants to complete the authorization process for your Salesforce tenant.


Log In to Your Salesforce Org

You must log into a Salesforce org in order to run CLI commands that require access to the org.

Before you begin

  • You must have full admin access in a Salesforce Enterprise account.

  • You must install or update Node.js. The Salesforce CLI requires Node.js to run. We recommend using Node.js 18.x or higher; Node.js 20.x is preferred.

  • You must have the Salesforce CLI installed.

The Salesforce user account to which the quarantine package is deployed must be the same one that will be used to authorize the Salesforce tenant for Cloud Malware protection and/or SaaS API Data Loss Prevention.

Procedure

  1. Open a local terminal or command prompt.

  2. Navigate and set the current directory to your Salesforce DX project directory (this is the folder containing your sfdx-project.json file).

  3. Run the authorization command to initiate a web-based login flow:

    sf org login web --alias MyTargetOrg

    Where MyTargetOrg is an alias for your authorized org. You can use this alias in future CLI commands to easily refer to it without citing its full username.

    Note

    If your target Salesforce org is a sandbox environment, use the command

    sf org login web --alias MyTargetOrg --instance-url sandbox-instance-url

    Where:

    • MyTargetOrg is an alias for your authorized org.

    • sandbox-instance-url is the URL for your sandbox org.

  4. A browser window will open, prompting you to log in to your Salesforce org. Enter your username and password for the target org.

  5. After successful login, you will be prompted to allow access for the Salesforce CLI. Click Allow.

Example

Once authorized, your terminal will display a success message confirming the alias and username of the authorized org.


Set Permissions in Salesforce

Before authorizing a Salesforce org as a tenant for Cloud Malware protection or SaaS API Data Loss Prevention you must assign the proper permissions and deploy the Salesforce quarantine package to the Salesforce admin user account that will be used to authorize the tenant. This allows the quarantine response action to function in your environment.

The Salesforce admin user authorizing the tenant must have the System Administrator or equivalent role, with the following permissions enabled:

  • Systems permissions:

    • View All Data

    • Modify All Data

    • Query All Files

  • Custom permission set "Cisco Secure Access SF Quarantine Admin"

Note
If the Salesforce tenant authorization is revoked and then restored with a new admin user, that admin user will need the same permissions enabled and the quarantine package will need to be deployed for that user.

You need to do this only once for any Salesforce tenant; if you want to support both Cloud Malware and SaaS API DLP for a tenant, you need not do it twice for that tenant.

Before you begin

  • You must have full admin access in a Salesforce Enterprise account.

The Salesforce user account to which the permissions are applied must be the same one that will be used to authorize the Salesforce tenant for Cloud Malware protection and/or SaaS API Data Loss Prevention.

Procedure

  1. Log into your Salesforce Enterprise org with an account that has full admin access.

  2. Select Setup > Users > Profiles.

    The Permissions Setup Users interface.
  3. Locate and view the profile for the Salesforce admin user to authorize the Salesforce tenant.

    The Permissions User Profiles interface.
  4. Find and click System Permissions.

  5. If disabled, enable the following permissions:

    • View All Data

    • Modify All Data

    • Query All Files

      The Permissions All interface.
    • Approve Uninstalled Connected Apps

      This permission can be assigned only to users with a full Salesforce user license. It is not available for users with Salesforce Platform or other limited-access licenses.

  6. If the API Access Control permission is enabled, allow the app Cisco Secure Access DLP.

  7. Find and click Custom Tab Settings.

    The Permissions Custom Tab Settings interface.
  8. Locate Cisco Secure Access SF Quarantines and set the value to Default On.

  9. Click Save.

  10. Find and click Permission Sets.

    The Permissions Permission Sets interface.
  11. Locate and click Cisco Secure Access SF Quarantine Admin.

  12. Click Manage Assignments.

  13. Click Add Assignment.

  14. From the list of users, select the Salesforce administrator to authorize the Salesforce tenant, then click Next.

    The Permissions Cisco Secure Access Sfquaratine Admin1 interface.The Permissions Cisco Secure Access Sfquaratine Admin2 interface.
  15. Click Assign.