Provides instructions for completing the Enable SaaS API Data Loss Prevention for Salesforce Tenants workflow in Cisco Secure Access. You must have full admin access to the Secure Access dashboard.
Secure Access supports SaaS API DLP protection in Salesforce Enterprise Grid deployments for both production and sandbox development for:
-
files uploaded to your Salesforce Enterprise Grid deployment in the Sales Cloud and Service Cloud.
-
files exchanged in Salesforce chatter posts.
-
chatter posts exchanged with your tenant.
-
core sObjects residing in your tenant.
-
custom sObjects residing in your tenant.
It may take up to 24 hours after a new custom sObject is created for the system to start scanning that sObject.
To use this feature you must authorize the tenant using the procedure described below. Once the tenant is authorized, for each file, chatter post, core sObject, or custom sObject residing in the tenant, when Secure Access finds data in violation of an enabled SaaS API rule it will enforce the action of that rule.
Before you begin
-
You must have full admin access to the Secure Access dashboard. See Manage Accounts.
-
You must have full admin access in a Salesforce Enterprise Grid account.
-
You must install or update
Node.js. The Salesforce CLI requiresNode.jsto run. We recommend usingNode.js18.x or higher;Node.js20.x is preferred. -
You must install the Salesforce CLI. This is the primary tool for interacting with Salesforce orgs and managing Salesforce DX projects.
-
You must log in to the Salesforce org you intend to authorize as a tenant.
-
You must Download the Salesforce quarantine package and install it for your Salesforce tenant. This enables Secure Access to support the quarantine response action for Salesforce files. (If you have already done this to support Cloud Malware Protection for this tenant, you need not do it again.)
-
You must set the appropriate systems permissions in your Salesforce deployment. (If you have already done this to support Cloud Malware Protection for this tenant, you need not do it again.)
The Salesforce user account to which the quarantine package is deployed and permissions are applied must be the same one that will be used to authorize the Salesforce tenant for SaaS API Data Loss Prevention.