Reminder: Complete IIQ Salesforce Connector Migration to External Client App by October 1st, 2026

This is a reminder for IdentityIQ (IIQ) customers still using Basic Authentication or Salesforce Connected App OAuth with the Salesforce connector.

On October 1st, 2026, SailPoint will no longer support non-ECA authentication for the IIQ Salesforce connector. After that date, remaining Basic Auth and Connected App configurations may fail Test Connection, aggregation, and provisioning.

This follows:

Why This Change?

Salesforce is replacing Connected Apps with External Client Apps (ECA) for third-party API access. Starting Spring ’26, customers cannot create new Connected Apps in the UI or API without Salesforce Support. ECA does not support username/password (Basic Auth).

SailPoint aligned the IIQ Salesforce connector to ECA using OAuth 2.0.

Action Required

Current Configuration Action by October 1st, 2026
Basic Auth (username + password) Required. Recreate auth as a local ECA using JWT, Client Credentials, or Refresh Token.
OAuth 2.0 via Connected App (JWT, Client Credentials, or Refresh Token) Required. Recreate the Salesforce-side app as a local ECA. IIQ grant-type settings stay similar; Consumer Key / Secret and related credentials must come from the ECA.
Already on local ECA with a successful Test Connection and aggregation No further auth migration. Confirm you are on a supported IIQ patch that includes ECA support.

IIQ customers create and own a local ECA in their Salesforce org. This is not the Identity Security Cloud AppExchange managed package.

Timeline

Milestone Date
First customer notice and setup guidance May 1st, 2026 Action Required
Deprecation of Basic Auth and Connected App OAuth Jun 18th, 2026 FINAL NOTICE
Support cutoff for non-ECA authentication Oct 1st, 2026

What happens if you do not migrate

After October 1st, 2026:

  • Test Connection, account/entitlement aggregation, and provisioning will fail.

  • SailPoint Support will direct remaining Basic Auth / Connected App cases to complete ECA migration.

  • New Salesforce orgs and rebuilt applications cannot rely on Connected Apps.

Help

If you have already migrated and Test Connection plus aggregation succeed on ECA, you can ignore this reminder.

We heard that Salesforce has extended password support through the end of the year.
Does SailPoint still support password authentication only through October 1?

There are no plans to extend it. Please reach out to your CSM in case of any challenges.