Overview
SSPM provides visibility into the configuration and security posture of your connected SaaS applications. Cato continuously reviews the application settings and compares them to the recommended posture defined by Cato’s research team. This helps identify misconfigurations that can increase risk, such as authentication settings, third-party integrations, and data-sharing controls.
Posture data appears in the Applications dashboard, where you can view posture scores and the highest-severity findings across connected applications. You can review each posture check from the Posture page, including the issue details, status, and remediation action required to pass the check.
For more information, see Reviewing the Security Posture of Your SaaS Applications (SSPM).
To configure the SSPM integration, you need to:
- Configure the required settings in the SaaS application
- Create the API connector in the CMA
A SaaS Security license is required for SSPM.
Configuring the Salesforce Integration
To configure the Salesforce integration, create a connected app.
Prerequisites
- You must enable API access in your Salesforce account
Step 1: Configure the Integration in your Salesforce Tenant
In your Salesforce tenant, identify the Consumer Key and Consumer Secret to enter into the CMA.
To configure the Salesforce integration:
Complete the following steps to configure the Salesforce integration:
Create an Integration User and assign the required permission set:
- In your Salesforce tenant, open Setup by clicking on the gear icon in the top right of the screen.
- Search for Users and open the Users page
- Click New User and add these details:
- User License: Salesforce
- Profile: Standard User
- Click Save.
- In the Setup search, search for Permission Sets and click New.
- Add a label and click Save.
- Open System Permissions, click Edit, and enable these permissions:
- API Enabled
- API Only Users
- View Setup and Configuration
- Customize Application
- View all External Client Apps
- Under Object Settings, great Read access for:
- Allowed Email Domain
- Email Services Function
Navigate to Manage Assignments > Add Assignment, select the integration user from Step 3, and assign.
Create a new external client app:
In your Salesforce tenant, open Setup by clicking on the gear icon in the top right of the screen.
Search for External Client App Manager.
Click New External Client App.
-
In the Basic Information section, add these details:
External Client App Name:
Cato SaaS PostureContact Email: An admin email address (Salesforce sends identity-verification codes here)
Distribution State: Local
-
Expand the API (Enable OAuth Settings) section and configure:
Enable OAuth: Check the checkbox
Callback URL:
https://cc.catonetworks.com/redirect/cas/salesforce/callbackSelected OAuth Scopes: Select Manage user data via APIs (api)
Click Create.
Retrieve the Consumer Key and Consumer Secret:
On the External Client App detail page of the app you created, open the Settings tab.
Expand OAuth Settings and click Manage Consumer Details.
Complete the verification steps
Copy and save the Consumer Key and Consumer Secret so they can be entered into the CMA.
Identify the Base URL:
Navigate to Setup > Company Settings > My Domain and copy and save the Current My Domain URL field so it can be entered into the CMA.
Step 2: Create the API Connector in the CMA
After you have set up an integration with the required application, add the details in the CMA.
To create the API connector in the CMA:
- From the navigation menu, click Resources > Integrations.
- Click the Configured Integrations tab.
- Click New.
The New Integration panel opens. - Select the SaaS Application you want to add.
- In the Capability drop-down select SaaS Posture.
- Add the details created during step one.
Base URL: My Domain URL
Client ID: Consumer Key
Client Secret: Consumer Secret
- Click Save.
The app is visible on the Integrated Apps table with a Connected status.
0 comments
Please sign in to leave a comment.