Connect a SaaS application ↗
To detect posture risks, applications must first be connected to Cortex SaaS Security and have the necessary permissions to scan SaaS application settings. During data connection, Cortex SaaS Security prompts you for the configuration information required to establish a connection with the SaaS app. The configuration information that SaaS Security requires differs from app to app, and you might need to collect configuration information prior to onboarding.
When you connect an application you may also be prompted to provide required for application connection, such as administrator credentials for a service account. The required information varies, and in many cases you must first take some actions on the SaaS app, such as creating an API key.
The following table provides links to detailed connection instructions for most applications. Where detailed instructions are not available for a particular SaaS application, the table includes the relevant onboarding steps.
| SaaS app connection steps |
|---|
| Aha.io |
| Asana |
| Atlassian |
| Automox |
| BusinessMap |
| Celonis |
| Cisco Duo |
| Cisco Meraki |
| Clickup |
| Contentful |
| Couchbase |
| Coveo |
| Databricks |
| DataDog |
| Gainsight |
| Grammarly |
| Harness |
| Intercom |
| Jamf Pro |
| Jumpcloud |
| Kustomer |
| Microsoft Entra |
| Monday |
| MongoDB |
| Mulesoft |
| Mural |
| <p>Nintex Workflow Cloud </p><p>Complete the following steps to connect to a Nintex Workflow Cloud API:</p><ol><li>Log in to a Nintex Workflow Cloud account that is assigned to the Global administrator role.</li><li>From the Apps and Tokens page in your Nintex Workflow Cloud settings, add an app.</li><li>Copy the Client ID and the Client Secret that is associated with your app.</li><li>During onboarding, provide the Client ID and the Client Secret that is associated with your app.</li></ol> |
| Office365 |
| Okta |
| Pagerduty |
| <p>Ping Identity </p><p>Complete the following steps to enable to connect a Ping Identity API:</p><ol><li>Log in to Ping Identity as an administrator assigned to either the Organization Admin or Environment Admin role.</li><li>Create a Ping Identity worker application, which will inherit your role assignments and enable access to the API. Copy the application's Client ID and Client Secret.</li><li>Copy your Environment ID and Region, which are shown on your environment page in Ping Identity.</li><li><p>During onboarding, provide the following information:</p><ul><li>The Client ID and Client Secret of the worker application</li><li>Your Environment ID and Region</li></ul></li></ol> |
| <p>Pipedrive </p><p>Complete the following steps to connect to a Pipedrive API:</p><ol><li>Log in to Pipedrive as an administrator and copy the administrator's personal API token.</li><li>During onboarding , provide the API token.</li></ol> |
| <p>Qualtrics </p><p>Complete the following steps to enable configuration information access through an administrator account. Your organization must be using Okta as an identity provider. MFA using one-time passcodes must be configured.</p><ol><li>Identify the Qualtrics XM administrator whose credentials you will supply to SSPM. The account must have Brand Administrator authority.</li><li><p>To enable SSPM to access the account using Okta credentials:</p><ol><li>Identify your Okta subdomain.</li><li>Generate and copy an MFA secret key.</li></ol></li><li>Identify your Organization ID. After you log in to Qualtrics XM, your organization ID is included in the Qualtrics XM URL. The URL format is <org-ID>.qualtrics.com.</li><li>Identify your SSO display name. To get the display name, go to AdminOrganization> SettingsSSO and open the Edit page for the SSO connection.</li><li>During onboarding, provide the information above.</li></ol> |
| Redis Labs |
| Salesforce |
| SAP Ariba |
| Sentryio |
| ServiceNow |
| Shopify |
| Slack |
| <p>Splunk </p><p>Complete the following steps to enable access to configuration information through an administrator account. Your organization must be using Okta as an identity provider. MFA using one-time passcodes must be configured.</p><ol><li>Identify the Splunk administrator whose credentials you will supply to SSPM.</li><li><p>To enable SSPM to access the account using Okta credentials:</p><ol><li>Identify your Okta subdomain</li><li>Generate and copy an MFA secret key</li></ol></li><li>Identify your Splunk app domain, which is a subdomain included in the Splunk Cloud URL. The URL format is <app_domain>.cloud.splunk.com or <app_domain>.splunkcloud.com.</li><li>During onboarding, provide your organization's Okta domain, the administrator credentials, the MFA secret key, and the Splunk app domain.</li></ol> |
| sumologic |
| <p>VMware </p><p>Complete the following steps to to connect to a VMWare API.</p><ol><li>Log in to VMWare Cloud Services using an account that is assigned to the Organization Owner role.</li><li><p>Generate and copy an API token for the organization. Configure the API key to these specifications:</p><ul><li>Limit Organization Roles access to the Organization Owner role.</li><li>Limit Service Roles to Skyline Advisor.</li><li>Select the OpenID scope.</li><li>(Optional) Select the email preference option to be notified when the token is about to expire.</li></ul></li><li>Copy your Organization ID, which you can access from your profile.</li><li>(Optional) Activate MFA for tokens that are associated with the account, and copy the MFA secret key for the account.</li><li>During onboarding, provide the API token and your organization ID. If you configured MFA for tokens, also provide your MFA secret key.</li></ol> |
| Workday |
| Wrike |
| Youtrack |