Salesforce + Microsoft Defender Integration — CRM Threat Protection
Salesforce + Microsoft Defender Integration connects Salesforce to Microsoft Defender for Cloud Apps — which ships a native, Microsoft-documented app connector for Salesforce — so security teams can govern CRM activity with Microsoft security tooling: login and admin activity monitoring, anomaly detection for suspicious logins, mass exports, and unusual sharing, OAuth app governance, Conditional Access session controls where Salesforce signs in through Microsoft Entra ID SSO, and automated response through playbooks and Power Automate. Centralizing Salesforce alerts and logs in Microsoft Sentinel for SOC investigation is included where scoped.
What this engagement is
This service secures Salesforce with the Microsoft security stack. Its foundation is the native Salesforce app connector in Microsoft Defender for Cloud Apps — a current, Microsoft-documented integration that collects Salesforce login events, the Setup Audit Trail (reaching about seven days back at initial connection), and Salesforce Event Monitoring data where the org licenses it (initial history ranging from roughly one to thirty days depending on license), enabling activity policies and anomaly detection over real CRM telemetry. On that foundation IT Partner configures detections for compromised accounts, suspicious logins, mass exports, and unusual sharing; OAuth app governance for third-party apps connected to Salesforce; Conditional Access App Control session policies where Salesforce authenticates through Microsoft Entra ID SSO; and automated response — disabling accounts, revoking tokens, notifying the SOC in Teams — through playbooks and Power Automate where licensing and API access allow. Where the client runs Microsoft Sentinel, Salesforce alerts and logs are centralized there for correlation with identity, endpoint, and cloud signals. This is app governance of Salesforce through Defender for Cloud Apps — not endpoint antivirus for Salesforce, which is not a meaningful concept for a SaaS CRM.
Success criteria
What you receive
How the work unfolds
Confirm business objectives, Salesforce security concerns, in-scope Salesforce orgs, Microsoft tenant details, stakeholders, acceptance criteria, and any compliance or SOC workflow requirements.
Validate Salesforce, Microsoft Defender for Cloud Apps, Microsoft Entra ID, Power Automate, and Microsoft Sentinel prerequisites; confirm licensing, Event Monitoring availability, SSO status, API permissions, administrative access, and pilot user groups.
Connect the native Salesforce app connector, validate ingestion of login events and Setup Audit Trail data (about seven days of history at connection) and Event Monitoring data where licensed, and confirm connector health.
Define and configure the monitoring, anomaly detection, activity policies, and OAuth app governance approach — including which Salesforce roles, privileged users, OAuth apps, and export activities require enhanced monitoring.
Where Salesforce authenticates through Microsoft Entra ID SSO, configure the agreed Conditional Access App Control session policies — piloted or run in report-only mode before enforcement, with break-glass considerations agreed.
Configure approved playbooks and Power Automate flows: disable compromised accounts, revoke suspicious OAuth tokens, and notify SOC teams via Teams — enabled in production only after client approval.
Where in scope, centralize Salesforce alerts and logs in Microsoft Sentinel, correlate Salesforce events with other security signals, and deliver SOC playbooks for the agreed CRM-specific threats.
Validate event flow, alert generation, session-control behavior, Sentinel incident creation, and approved remediation workflows with agreed test scenarios; tune thresholds; and hand over configuration and operational guidance with acceptance against the agreed scope.
Prerequisites
Who does what
IT Partner
- Connect Salesforce to Microsoft Defender for Cloud Apps via the native app connector and validate telemetry ingestion.
- Configure anomaly detection and activity policies for suspicious logins, mass exports, unusual sharing, and privileged activity per the agreed scope.
- Configure OAuth app governance and alerting for third-party app access and suspicious token usage.
- Configure Conditional Access App Control session policies where Microsoft Entra ID SSO and licensing prerequisites are in place, with piloting before enforcement.
- Configure approved automated remediation through playbooks and Power Automate where licensing and Salesforce API access allow.
- Centralize Salesforce alerts and logs in Microsoft Sentinel and deliver SOC playbooks for CRM-specific threats, where in scope.
- Validate technical prerequisites and identify licensing, access, telemetry, or configuration gaps that affect the implementation.
- Test configured detections, log flow, alert routing, and approved remediation actions with customer-provided test accounts or scenarios.
- Provide implementation handover, configuration summary, and operational guidance for customer security and Salesforce administrators.
Your team
- Provide a project sponsor, technical contacts, and timely access to Salesforce, Microsoft Entra ID, Microsoft Defender for Cloud Apps, Microsoft Sentinel, and Power Automate administrators.
- Confirm and maintain required licenses: Microsoft Defender for Cloud Apps, Salesforce Event Monitoring where telemetry depth requires it, Microsoft Entra ID P1/P2 per the policy design, Power Automate premium where remediation flows are in scope, and Sentinel/Azure capacity.
- Provide or approve administrative access, API permissions, connected app permissions, service accounts, consent grants, and any required Salesforce or Microsoft tenant changes.
- Confirm whether Salesforce authenticates through Microsoft Entra ID SSO and approve the Conditional Access policy design, pilot rollout, exclusions, and enforcement timing.
- Identify Salesforce privileged users, high-risk roles, sensitive data areas, critical integrations, and existing OAuth applications to monitor or protect.
- Review and approve alert thresholds, remediation actions, Teams notification recipients, SOC escalation paths, and any account disablement or token revocation automation before production use.
- Provide test users, pilot groups, and validation scenarios for suspicious login, export, OAuth, and API monitoring tests.
- Participate in user impact review, testing, change approval, and acceptance of implemented controls.
- Own ongoing operation after handover: monitoring alerts, responding to incidents, maintaining licenses, and updating approvals as environments change.
What's not included
Limitations & technical notes
Frequently asked questions
What is the Salesforce + Microsoft Defender Integration service?
IT Partner connects Salesforce to Microsoft Defender for Cloud Apps — using its native Salesforce app connector — so your security team can monitor and govern CRM activity with Microsoft security tooling: anomaly detection for suspicious logins, mass exports, and unusual sharing; OAuth app governance; Conditional Access session controls where Salesforce uses Entra ID SSO; automated response through playbooks and Power Automate; and Salesforce alerts centralized in Microsoft Sentinel where scoped.
Is there a native Microsoft integration for monitoring Salesforce?
Yes. Microsoft Defender for Cloud Apps ships a native, Microsoft-documented app connector for Salesforce. Once connected, it collects Salesforce login events, the Setup Audit Trail — reaching about seven days back at initial connection — and Event Monitoring data where your Salesforce licensing includes it, enabling activity policies and anomaly detection over real CRM telemetry.
Is this antivirus for Salesforce?
No — and nothing is. Salesforce is a SaaS application, so endpoint antivirus is not the relevant control. What this service delivers is app governance: Defender for Cloud Apps monitors Salesforce activity, detects anomalous behavior, governs OAuth apps connected to your org, and — with Entra ID SSO — controls risky sessions. That is the Microsoft-supported way to secure a SaaS CRM.
What Salesforce threats can this integration help detect?
Compromised accounts, suspicious or impossible-travel logins, mass exports, unusual sharing behavior, suspicious OAuth token usage, unauthorized third-party integrations, and anomalous privileged activity. With Sentinel in scope, Salesforce events also correlate with identity, endpoint, and cloud signals for SOC investigation.
Can risky Salesforce sessions be controlled in real time?
Yes, where Salesforce authenticates through Microsoft Entra ID SSO. Conditional Access App Control can then enforce session policies — for example blocking sessions from anonymizing networks or requiring compliant devices for high-privilege users. Policies are piloted or run report-only before enforcement, with exclusions and break-glass accounts agreed.
Do we need Salesforce Event Monitoring?
The connector works without it — login events and the Setup Audit Trail flow regardless — but Salesforce Event Monitoring, a license-dependent add-on, substantially deepens the activity telemetry available to Defender for Cloud Apps (with initial history from roughly one to thirty days depending on license). IT Partner confirms your telemetry depth during readiness validation and designs detections around what your licensing actually provides.
What Microsoft licensing is required?
Microsoft Defender for Cloud Apps licensing — standalone or through a qualifying Microsoft 365 plan; Microsoft Entra ID P1/P2 per the Conditional Access design, with P2 for risk-based policies; Power Automate premium connector licensing where remediation flows call Salesforce APIs; and a Microsoft Sentinel workspace where Sentinel is in scope. Exact readiness is confirmed during scoping.
Can the integration respond to threats automatically?
Yes, where licensing and API access allow. Approved playbooks and Power Automate flows can disable compromised accounts, revoke suspicious OAuth tokens, and notify SOC teams via Microsoft Teams. Every automated action is reviewed and approved by you before it is enabled in production.
How does Microsoft Sentinel fit in?
Where in scope, Salesforce alerts and logs are centralized in Microsoft Sentinel for compliance auditing and SOC investigation, correlated with your other security signals, and backed by SOC playbooks for CRM-specific threats such as suspicious logins, mass exports, and unauthorized integrations.
Can this stop users exporting data from the Salesforce UI?
Detection and alerting on mass exports is in scope. Hard real-time blocking of some UI-level actions, however, requires Salesforce-side controls such as Salesforce Shield — a Salesforce product outside Microsoft tooling. If UI export blocking is a requirement, IT Partner flags the Shield dependency during scoping.
How long does the integration take, and how is it priced?
The service is billed hourly at the published rate, with total effort scoped per project. A standard engagement is planned at five days; the final timeline depends on licensing readiness, SSO status, automation scope, and Sentinel requirements.
What happens after the integration is completed?
Your security team operates the configured detections, session controls, Sentinel correlation, and approved remediation flows, with IT Partner's handover documentation and operational guidance. Ongoing SOC monitoring, incident response, and maintenance are not included by default; they are available as optional extra-cost add-ons through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.