Following our initial advisory, this second announcement confirms that the SailPoint External Client App (ECA) package is now live on Salesforce AgentExchange. The ECA is now the only supported authentication method for the ISC Salesforce connector(VA and SaaS). The 90-day migration window opens July 1, 2026 use the time between now and then to install the ECA package, align your team, and validate in sandbox (available June 24)
Note : Do not migrate to ECA Authentication if you use the Salesforce Activity Data Insights (ADI) connector.
Why is this happening?
Salesforce is retiring its Connected App framework for external integrations and requires migration to External Client Apps (ECA). This is a Salesforce platform change, not a SailPoint product update. SailPoint has updated the ISC Salesforce connector to comply and published the ECA package on AgentExchange. You must complete migration by September 30, 2026 to maintain connectivity.
Key Dates
Plan your migration around these dates. Use the sandbox first to validate before production goes live.
| Milestone | Date |
|---|---|
| Sandbox availability | June 24, 2026 |
| Production availability | June 29, 2026 |
| Migration window opens | July 1, 2026 |
| Migration window closes | September 30, 2026 |
| Legacy auth permanently removed | October 1, 2026 |
Deadline: September 30, 2026. After this date, Basic Auth and all OAuth 2.0 Connected App flows (JWT, Refresh Token, Client Credentials) are permanently removed. Connectors not migrated will lose Salesforce connectivity provisioning, aggregation, and all connector operations will fail.
What You Need to Do?
Install the SailPoint ECA package from Salesforce Agent Exchange and reconfigure your connector with ECA Authentication before September 30, 2026 ; connectors using deprecated authentication methods will stop working after that date.
What Is Changing?
Salesforce is replacing Connected Apps with External Client Apps for all external API integrations. The table below shows exactly what changes in the ISC Salesforce connector(VA and SaaS)
| Area | Before (Deprecated) | After (Required) |
|---|---|---|
| Auth Framework | Salesforce Connected App | Salesforce External Client App (ECA) |
| OAuth Flow | JWT / Refresh Token / Client Credentials / Basic | OAuth 2.0 Authorization Code Grant only |
Deprecated Authentication Methods
The following methods are deprecated as of July 01, 2026. They remain accessible via the backward compatibility toggle during the 90-day window. All deprecated methods and the legacy Connection Settings UI will be permanently removed on September 30, 2026.
| Method | Status | Action Required By |
|---|---|---|
| Basic Authentication | Deprecated | September 30, 2026 |
| OAuth 2.0 - JWT Bearer | Deprecated | September 30, 2026 |
| OAuth 2.0 - Refresh Token | Deprecated | September 30, 2026 |
| OAuth 2.0 - Client Credentials | Deprecated | September 30, 2026 |
| External Client App (ECA) | Supported — New Default | — |
Note: The backward compatibility toggle allows temporary reversion to a deprecated method if you encounter issues during migration. This toggle will be removed when the deprecation window closes and the deprecated connection settings UI will no longer be available.
Migration Steps
Complete all three steps by September 30, 2026
Step 1 - Install the External Client App Managed Package from Salesforce AgentExchange
-
Go to the Salesforce AgentExchange.
-
Search for the SailPoint ECA-SailPoint Identity Security for Salesforce
-
Enter your Salesforce credentials to authorize the installation.
-
Select Install for All Users (or your preferred security level) within your Salesforce organization.
Step 2 - Configure ECA Authentication in the ISC Salesforce Connector
In the Identity Security Cloud UI, open the Salesforce connector and go to the ECA Authentication section.
-
Turn on the Enable External Client App (ECA) toggle.
-
Under Client Configuration, add the following key-value pair:
-
Key: host_name
-
Value: Token URL for your environment — test.salesforce.com (sandbox) or login.salesforce.com (production), depending on your Salesforce tenant configuration
-
-
Click on Authorize and complete the OAuth 2.0 Authorization Code Grant flow.
-
Select Save.
-
Review the configuration and select Test Connection to verify the integration.
Note: The service account used to authorize the ECA must have adequate permissions to manage the required Salesforce objects.
Step 3 - Validate and Move to production
-
Run a test aggregation to confirm accounts and entitlements are returned correctly.
-
Validate provisioning operations (create, update, disable) against a test account.
-
Confirm lifecycle events are flowing as expected.
-
Once validated, move to production
Important Considerations for ECA Authentication
- Maximum Concurrent Tokens
Salesforce limits active refresh tokens to five per user per External Client App. If a sixth connection is requested, Salesforce automatically and silently revokes the oldest active token. No warning is issued
- Revoked Token Reuse - Critical Risk
If an authenticated source attempts to authenticate using a previously revoked token (such as the silently dropped oldest token), Salesforce treats the attempt as a critical security threat. As a result, Salesforce immediately invalidates all active refresh tokens and sessions for that user across all clients.
Important: If this occurs, you must reauthorize the integration to continue. To avoid this scenario, ensure that no more than five concurrent authenticated connections are active per user for a given ECA.
- Backward Compatibility Toggle
A backward compatibility toggle is available in the connector UI during the 90-day deprecation window. This allows you to temporarily revert to a previously working legacy configuration if issues arise during migration. This toggle will be permanently removed when the window closes and will not be available post-deprecation.
Action Checklist
The migration window opens July 1, 2026. Start preparing now to avoid last-minute rush.
-
Share this announcement with your Salesforce admin and identity governance team today.
-
Align internally on ECA setup, AgentExchange installation approval, and test scheduling.
-
Start in sandbox (available June 24) install the ECA package and validate before production goes live.
-
Install the ECA package from Salesforce AgentExchange before July 1, 2026.
-
Configure the connector with the correct host_name for each environment (sandbox and production).
-
Complete validation in non-prod before promoting to production (available June 29).
-
Use the backward compatibility toggle only as a temporary fallback not a substitute for migration.
-
Contact your SailPoint PM or Customer Success Manager for migration support
Deadline: September 30, 2026,
After this date, legacy authentication is permanently removed. Connectors not migrated will lose Salesforce connectivity provisioning, aggregation, and all connector operations will fail.
Support and Resources
- Contact your SailPoint Product Manager or Customer Success Manager for migration support.