SOLVED

MCAS and Salesforce - Do we need SF shield ?

%3CLINGO-SUB%20id%3D%22lingo-sub-2453103%22%20slang%3D%22en-US%22%3EMCAS%20and%20Salesforce%20-%20Do%20we%20need%20SF%20shield%20%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2453103%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EWe%20asked%20Microsoft%20and%20Salesforce%20if%20the%20SF%20shield%20licenses%20were%20a%20requirement%20to%20improve%20monitoring%2C%20neither%20were%20able%20to%20respond%20so%20I'm%20reaching%20out%20to%20the%20community.%3C%2FP%3E%3CP%3EWe%20have%20connected%20our%20SF%20instance%20to%20MCAS%20following%20the%20available%20documentation.%20We%20had%20to%20do%20some%20tinkering%20to%20bypass%20having%20to%20use%20a%20Sysadmin%20profile.%20SF%20shows%20up%20as%20connected%20and%20we%20get%20the%20users%20correlation%20between%20Azure%2FO365%2FMCAS%20and%20SF%20plus%20some%20login%2Flogout%20events.%3C%2FP%3E%3CP%3ENow%20we%20don't%20get%20a%20lot%20of%20data%2Falerts%20from%20Salesforce%2C%20will%20this%20be%20improved%20by%20adding%20the%20extended%20event%20monitoring%20provided%20by%20SF%20shield%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20any%20experiences%20and%20feedback%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERobert%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2453103%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EApp%20Connectors%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECloud%20App%20Security%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2468414%22%20slang%3D%22en-US%22%3ERe%3A%20MCAS%20and%20Salesforce%20-%20Do%20we%20need%20SF%20shield%20%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2468414%22%20slang%3D%22en-US%22%3EHi%20Robert%2C%3CBR%20%2F%3E%3CBR%20%2F%3EYes%2C%20we%20do%20require%20SF%20shield%20for%20additional%20logs%20to%20be%20pulled%20to%20MCAS.%20Otherwise%20Salesforce%20only%20shares%20login%2Flogout%20details%20as%20you%20are%20observing.%3CBR%20%2F%3E%3CBR%20%2F%3ERegards%2C%3CBR%20%2F%3ERajan.%3C%2FLINGO-BODY%3E
Regular Visitor

Hi,

We asked Microsoft and Salesforce if the SF shield licenses were a requirement to improve monitoring, neither were able to respond so I'm reaching out to the community.

We have connected our SF instance to MCAS following the available documentation. We had to do some tinkering to bypass having to use a Sysadmin profile. SF shows up as connected and we get the users correlation between Azure/O365/MCAS and SF plus some login/logout events.

Now we don't get a lot of data/alerts from Salesforce, will this be improved by adding the extended event monitoring provided by SF shield ?

 

Thanks for any experiences and feedback,

 

Robert

 

 

1 Reply
best response confirmed by rvonbism71 (Regular Visitor)
Solution
Hi Robert,

Yes, we do require SF shield for additional logs to be pulled to MCAS. Otherwise Salesforce only shares login/logout details as you are observing.

Regards,
Rajan.