Salesforce | Insights

Learn how to create a Salesforce connector in BeyondTrust Identity Security Insights.

Prerequisites

Before you configure the Salesforce connector, ensure the following requirements are met.

Salesforce access

  • You have System Administrator access to your Salesforce organization.
  • You can create external client applications under App Manager.
  • You can create users and custom profiles.
  • A Salesforce license is available for the integration user.

Identity Security Insights access

  • You have administrator access to Identity Security Insights.
🚧

Important

Third-party documentation is subject to change. Updates might not be reflected in BeyondTrust documentation. For the most up-to-date information, refer to Salesforce documentation.

Step 1: Find your Salesforce domain

Salesforce login domains vary by org type — production, sandbox, QA, lab, and Developer Edition environments each use a different URL. Retrieve the exact login domain so you can enter it correctly when creating the connector.

  1. Log in to Salesforce as a System Administrator in the org you want to connect.
  2. In the top-right corner of Lightning Experience, click the gear icon (⚙), then select Setup. The Setup page opens in a new tab.
  3. In the Quick Find box on the left side of the Setup page, enter My Domain, then select My Domain under Company Settings.
  4. On the My Domain page, locate the Current My Domain URL field. Copy this value. You will enter it in the connector's Domain field.
    ℹ️

    Ensure the URL you copy ends with .salesforce.com. If it does not, confirm with the Salesforce admin that you are viewing the correct field.

Step 2: Create custom profile

  1. Navigate to the Setup page by clicking on the gear icon.
  2. From Setup, enter Profiles in the Quick Find box, and select Profiles.
  3. Click New Profile.
  4. On the Clone Profile page:
    1. Select Minimum Access - Salesforce for existing profile.
    2. Enter BT Insights Connector as the profile name.
  5. Click Save.
  6. On the new profile page, under System, select System Permissions.
    Activate the following:
    • System
      • API Enabled
      • API Only User
      • Customize Application: Requires View Setup and Configuration, Manage Custom Permissions
      • Manage Auth. Provider: Requires Manage Users, Author Apex
      • Manage Package Licenses
      • Modify Metadata Through Metadata API Functions
      • View All Data: Requires Read and View All on all standard and custom objects, View Setup and Configuration, View All Forecasts, View Event Log Files, View Dashboards in Public Folders, View Reports in Public Folders, View Login Forensics Events, View Real-Time Event Monitoring Data
      • View all External Client Apps
      • View Roles and Role Hierarchy
      • View Setup and Configuration: Requires View Roles and Role Hierarchy
      • View Devices* (only available if Mobile Device Tracking feature is enabled)
    • Users
      • View all Users
  7. Click Save.

Step 3: Create an integration user

  1. From Setup, in the Quick Find box, enter Users, and then select Users.
  2. Click New User.
  3. Enter the details:
    1. First name: BT Insights Connector
    2. Last name: User
    3. Enter an email address and a unique username in the form of an email address. By default, the username is the same as the email address.
    4. Record the username to use it later.
    5. User License: Salesforce
    6. Profile: BT Insights Connector
  4. Click Save.

Step 4: Create external client application

  1. From Setup, in the Quick Find box, enter App Manager, and then select App Manager.
  2. Click New External Client App.
  3. On the New External Client App page:
    1. Enter external client app name: BT Insights Connector
    2. Enter contact email
    3. Under API (Enable OAuth Settings), check Enable OAuth
    4. Under App Settings
      1. Callback URL: Any URL starts with HTTPS as it won’t be used (https://localhost:8080)
      2. OAuth Scopes
        1. Select Manage user data via APIs (api) in Available OAuth Scopes
        2. Click the top triangle/arrow to move scope to Selected OAuth Scopes
    5. Under Flow Enablement
      1. Check Enable Client Credentials Flow
    6. Under Security, ensure that all checkboxes are unchecked.
  4. Click Create.

Configure the external client app policies

  1. On newly created External client app page
    On the Policies tab, click Edit
  2. Scroll to OAuth Flows and External Client App Enhancements, check Enable Client Credentials Flow.
  3. Run As (Username): Enter the username of the integration user created earlier.
  4. Click Save.

Record the Consumer Key and Secret

  1. On the Settings page, navigate to OAuth Settings
  2. Under App Settings, click Consumer Key and Secret
  3. Verify identity (if requested).
  4. Record Consumer Key and Consumer Secret. You need these for the final step.

Final step: Create the connector in Insights

  1. From Insights Home, select Pathfinder navigation menu > Connectors.
    The Connectors page displays.
  2. Click Total configured.
  3. Select Create Connector > Salesforce.
Saleforce connector settings
  1. Provide the following information to connect to Salesforce:
    • Name: A human-readable name for your Salesforce connector, typically the Salesforce org name.
    • Domain: Your Salesforce domain, e.g., https://your-domain.salesforce.com.
    • Consumer Key: Copy the Consumer Key recorded in Step 4.
    • Consumer Secret: Copy the Consumer Secret recorded in Step 4.
  2. Click Create Connector.

Navigate to Pathfinder navigation menu > Connectors > Total Configured to confirm the connector was successfully created and review connector settings.


©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.