This is a reminder for IdentityIQ (IIQ) customers still using Basic Authentication or Salesforce Connected App OAuth with the Salesforce connector.
On October 1st, 2026, SailPoint will no longer support non-ECA authentication for the IIQ Salesforce connector. After that date, remaining Basic Auth and Connected App configurations may fail Test Connection, aggregation, and provisioning.
This follows:
-
Action Required: IIQ Salesforce Connector Migration to External Client App — what is changing and how to configure local ECA
-
Migration: IIQ Salesforce Connector to ECA — FINAL NOTICE — deprecation effective July 1st, 2026
Why This Change?
Salesforce is replacing Connected Apps with External Client Apps (ECA) for third-party API access. Starting Spring ’26, customers cannot create new Connected Apps in the UI or API without Salesforce Support. ECA does not support username/password (Basic Auth).
SailPoint aligned the IIQ Salesforce connector to ECA using OAuth 2.0.
Action Required
| Current Configuration | Action by October 1st, 2026 |
|---|---|
| Basic Auth (username + password) | Required. Recreate auth as a local ECA using JWT, Client Credentials, or Refresh Token. |
| OAuth 2.0 via Connected App (JWT, Client Credentials, or Refresh Token) | Required. Recreate the Salesforce-side app as a local ECA. IIQ grant-type settings stay similar; Consumer Key / Secret and related credentials must come from the ECA. |
| Already on local ECA with a successful Test Connection and aggregation | No further auth migration. Confirm you are on a supported IIQ patch that includes ECA support. |
IIQ customers create and own a local ECA in their Salesforce org. This is not the Identity Security Cloud AppExchange managed package.
Timeline
| Milestone | Date |
|---|---|
| First customer notice and setup guidance | May 1st, 2026 Action Required |
| Deprecation of Basic Auth and Connected App OAuth | Jun 18th, 2026 FINAL NOTICE |
| Support cutoff for non-ECA authentication | Oct 1st, 2026 |
What happens if you do not migrate
After October 1st, 2026:
-
Test Connection, account/entitlement aggregation, and provisioning will fail.
-
SailPoint Support will direct remaining Basic Auth / Connected App cases to complete ECA migration.
-
New Salesforce orgs and rebuilt applications cannot rely on Connected Apps.
Help
-
Setup steps: Action Required — IIQ Salesforce Connector Migration to External Client App
-
Prior deprecation notice: FINAL NOTICE
-
Salesforce ECA: External Client Apps
-
Questions or a blocked production cutover: your SailPoint Customer Success Manager, Product Manager, or a Support case (include IIQ version/patch, Salesforce org type, and current auth type)
If you have already migrated and Test Connection plus aggregation succeed on ECA, you can ignore this reminder.