Blog
Migration: IIQ Salesforce Connector to ECA (FINAL NOTICE)
Author
Angel_Tawade
SailPoint
Following the initial announcement on May 1, 2026, this is the final, consolidated notice for all IIQ customers using the Salesforce connector. Please read in full — action is required regardless of your current authentication method.
Action Required
- Engage your Salesforce Administrator before making any changes in IIQ. This change starts on the Salesforce side. Begin this conversation today — your Salesforce admin needs to set up the ECA before IIQ can be reconfigured.
- Note for your Salesforce Admin: When creating the ECA, set the Distribution State to Local (not Packaged). IIQ integrates only with local ECAs — this setting must be correct from the start.
- Migration deadline: 180 days from the date of this post. After this window closes, SailPoint Support will not accept queries related to Connected App or basic auth configurations. No extensions will be granted.
What Is an External Client App (ECA)?
A Salesforce External Client App (ECA) is Salesforce's next-generation replacement for Connected Apps as the mechanism for managing external API access. ECAs provide granular OAuth policy controls, improved token lifecycle management, and represent Salesforce's strategic direction for all external integrations going forward.
Importantly, the OAuth 2.0 flows you use today do not change. If you currently authenticate via JWT Bearer, Client Credentials, or Refresh Token, those same flows are supported via ECA. The ECA replaces the Salesforce-side application object — not the authentication flow or the IIQ configuration pattern.
Salesforce documentation your admin will need:
- Create a Local External Client App — step-by-step guide to creating the ECA in your Salesforce org. When prompted for Distribution State, select Local (not Packaged). IIQ integrates with a local ECA only.
- Set Up OAuth Flows for External Client Apps — covers how to configure and enable each supported OAuth flow (JWT Bearer, Client Credentials, Web Server/Refresh Token) within an ECA. Share this with your Salesforce admin alongside the IIQ flow you have selected.
Note: Refer to the May 1, 2026 IIQ Salesforce Connector announcement for ECA deployment guides (JWT, Client Credentials, Refresh Token) under the Salesforce Local ECA - deployment & authentication section of the previous announcement.
What is changing?
Effective from July 01, 2026, SailPoint is formally deprecating two authentication paths for the IIQ Salesforce connector:
- Basic authentication (username + password)
- All OAuth 2.0 flows configured via a Salesforce Connected App — JWT Bearer, Client Credentials, and Refresh Token
Going forward, all customers must authenticate through a Salesforce External Client App (ECA) using one of the supported OAuth 2.0 flows.
| Authentication method | Status | Path forward |
|---|---|---|
Basic auth (username + password) | Deprecated | Must migrate to ECA + OAuth 2.0 |
JWT Bearer Connected App | Deprecated | Reconfigure to JWT Bearer via ECA |
Client Credentials Connected App | Deprecated | Reconfigure to Client Credentials via ECA* |
Refresh Token Connected App | Deprecated | Reconfigure to Refresh Token via ECA |
JWT / Client Credentials / Refresh Token via ECA | Supported | No change required |
Client Credentials via ECA is supported on 8.4p4, If you are on an earlier version and plan to use this flow, upgrade your IIQ instance as part of your migration plan.
Who Is Impacted?
All IIQ customers using the Salesforce connector are impacted. What you need to do depends on your current authentication method:
Basic authentication users:
- You must migrate to OAuth 2.0. Basic authentication is no longer supported. Work with your Salesforce admin to create a local ECA and select an OAuth 2.0 flow (JWT Bearer, Client Credentials, or Refresh Token) before reconfiguring IIQ.
Connected App OAuth users (JWT Bearer, Client Credentials, or Refresh Token):
- You need to reconfigure — not rebuild. Your OAuth flow stays the same. The Salesforce-side Connected App must be recreated as a local ECA, and IIQ updated to reference the new ECA credentials. The IIQ configuration pattern for your chosen flow does not change.
ECA-based OAuth users:
- No action required. You are already on the supported path.
How to Migrate or Reconfigure?
Complete all steps in this order. Steps 1–2 are Salesforce-side. Steps 3–5 are IIQ-side.
- Engage your Salesforce Administrator immediately. This is the most important first action. Your Salesforce admin must create and deploy a local ECA in your Salesforce org before any IIQ changes can be made. Begin this coordination now — do not wait until close to the deadline. Point them to: Create a Local External Client App.
- Confirm your current authentication method. Check your IIQ Salesforce application configuration — determine whether you are on Basic auth or a Connected App OAuth flow. Basic auth users need to select an OAuth 2.0 flow. Connected App OAuth users keep their existing flow.
- Choose your target ECA-based OAuth 2.0 flow. Select from:
- JWT Bearer
- Client Credentials (verify IIQ version support)
- Refresh Token
Your Salesforce admin needs this decision to configure the ECA with the correct policies and scopes.
- Deploy a local ECA in your Salesforce org. Work with your Salesforce administrator to create and configure the ECA. Two things to flag explicitly to your Salesforce admin:
- Set Distribution State to Local. This is step 6 in the Create a Local External Client App guide. IIQ connects to a local ECA only — do not select Packaged.
- Enable and configure the OAuth plugin for your chosen flow (JWT Bearer, Client Credentials, or Refresh Token). Refer to: Set Up OAuth Flows for External Client Apps. The ECA replaces your Connected App — your chosen OAuth flow stays the same.
- Set Distribution State to Local. This is step 6 in the Create a Local External Client App guide. IIQ connects to a local ECA only — do not select Packaged.
- Reconfigure the IIQ Salesforce application. Update your IIQ Salesforce application to reference the new ECA credentials. If you are a Connected App OAuth user, your OAuth flow configuration in IIQ remains the same — only the credentials change. If you are migrating from basic auth, you will also configure the OAuth flow settings for the first time.
- Validate before cutover. Run a test connection and account aggregation in a non-production environment. Confirm everything is working before switching production over.
Need help? Contact your SailPoint Product Manager or Customer Success representative for migration planning support. Support is available throughout the 180-day window.
After the migration window closes (post 180 days)
Starting Jan 1, 2027, the following applies:
- SailPoint Support will not accept, investigate, or escalate tickets related to Connected App or basic auth configurations.
- No patches, workarounds, or compatibility updates will be issued for deprecated authentication paths.
- Customers who have not completed migration will lose SailPoint support coverage for their Salesforce connector.
As an IIQ on-premises customer, this migration is your responsibility. SailPoint is here to support you during the window — but the deadline cannot be extended. Begin now.
Get support
- Contact your SailPoint Product Manager or Customer Success Manager for migration planning.
- Refer to the May 1, 2026 IIQ Salesforce Connector announcement for ECA deployment guides (JWT, Client Credentials, Refresh Token).
- Post questions in the SailPoint Community for peer and SailPoint team support.