Salesforce External Client App (ECA) Authentication – Clarification on Test Connection and Account Aggregation

Your understanding looks correct to me. Once ECA is enabled, authorized and saved, Test Connection and aggregation should be going through the ECA path. The migration steps also say to run Test Connection after ECA configuration, then a test aggregation to confirm accounts and entitlements are returned. So I would not assume Basic is expected by design here.

I would check if the source is still falling back to legacy settings. The backward compatibility toggle is available during the 90-day migration window, and if that is still on, the connector would use the old auth method for operations even though the ECA authorize step itself worked fine. Also confirm old Basic/OAuth values are not still being picked from the source config, and that host_name is set only to login.salesforce.com or test.salesforce.com.

If Salesforce still shows Basic after verifying all of that, I would refer to the ECA product announcement and reach out to Angel_Tawade or your SailPoint PM/CSM for migration support. Per the announcement, ECA is the supported path for connector validation and operations going forward, so they should be able to confirm why it is still logging as Basic in your tenant.