Cisco Secure Access Help

PDF

Cisco Secure Access Help

Enable SaaS API Data Loss Prevention for Salesforce Tenants

Want to summarize with AI?

Log in

Provides instructions for completing the Enable SaaS API Data Loss Prevention for Salesforce Tenants workflow in Cisco Secure Access. You must have full admin access to the Secure Access dashboard.


Secure Access supports SaaS API DLP protection in Salesforce Enterprise Grid deployments for both production and sandbox development for:

  • files uploaded to your Salesforce Enterprise Grid deployment in the Sales Cloud and Service Cloud.

  • files exchanged in Salesforce chatter posts.

  • chatter posts exchanged with your tenant.

  • core sObjects residing in your tenant.

  • custom sObjects residing in your tenant.

    Note
    It may take up to 24 hours after a new custom sObject is created for the system to start scanning that sObject.

To use this feature you must authorize the tenant using the procedure described below. Once the tenant is authorized, for each file, chatter post, core sObject, or custom sObject residing in the tenant, when Secure Access finds data in violation of an enabled SaaS API rule it will enforce the action of that rule.

Before you begin

The Salesforce user account to which the quarantine package is deployed and permissions are applied must be the same one that will be used to authorize the Salesforce tenant for SaaS API Data Loss Prevention.

Procedure

  1. Navigate to Admin > Authentication.

  2. Under SaaS API Platforms, click to expand Salesforce.

    Authentication page displaying options for Salesforce and authorize new tenant
  3. In the DLP subsection, click Authorize New Tenant to add a Salesforce tenant to your Secure Access environment.

  4. In the Salesforce Authorization dialog, click the Salesforce Quarantine Package link and deploy the Salesforce quarantine package to your Salesforce tenant. This enables Secure Access to support the quarantine response action for Salesforce. (If you have already deployed the package to support Cloud Malware Protection for this tenant, you need not do it again.)

    Salesforce Authorization page displaying options for Salesforce Quarantine Package and next
  5. In the Salesforce Authorization dialog, check the checkboxes to verify you meet the prerequisites, then click Next.

  6. Enter the Tenant Name. If the tenant is a Salesforce sandbox, check Salesforce Sandbox. Click Next.

    Salesforce Authorization page displaying the option to proceed to the next step
  7. Click Next to be redirected to the Salesforce login page.

    Salesforce Authorization page displaying the option to proceed to the next step
  8. Log in to Salesforce with admin credentials to grant access.

    Salesforce page displaying the option to log in

    You are redirected to Secure Access and a message appears showing the integration was successful. It may be up to 24 hours for the integration to be confirmed and appear as Authorized.

  9. Click Done to complete.

    Salesforce Authorization page displaying the option for done
  10. The new tenant will appear on the Authorization page in the list under Salesforce.

    If you checked Salesforce Sandbox in Step 6, the tenant name will have [Sandbox] appended to it.

    Salesforce page displaying options for cloud malware and DLP