Onboard a Supported SaaS Application
Onboard a supported SaaS application to track and monitor misconfigurations and compliance violations.
To detect posture risks, applications must first be connected to SaaS Security and have the necessary permissions to scan SaaS applications settings. During onboarding, SaaS Security prompts you for the configuration information required to establish a connection with the SaaS app. The configuration information that SaaS Security requires differs from app to app, and you might need to collect configuration information prior to onboarding.
When you onboard a SaaS app, SaaS Security may prompt you for information used to connect to the SaaS app, such as administrator credentials for a service account. The required information varies from app to app, and in many cases you must first take some actions on the SaaS app, such as creating an API key.
The following table provides links to detailed onboarding instructions for most applications. Where detailed instructions are not available for a particular SaaS application, the table includes the relevant onboarding steps.
Available onboarding instructions
SaaS App Onboarding Instructions
Nintex Workflow Cloud
Complete the following steps to connect to a Nintex Workflow Cloud API:
Log in to a Nintex Workflow Cloud account that is assigned to the Global administrator role.
From the Apps and Tokens page in your Nintex Workflow Cloud settings, add an app.
Copy the Client ID and the Client Secret that is associated with your app.
During onboarding, provide the Client ID and the Client Secret that is associated with your app.
Ping Identity
Complete the following steps to enable to connect a Ping Identity API:
Log in to Ping Identity as an administrator assigned to either the Organization Admin or Environment Admin role.
Create a Ping Identity worker application, which will inherit your role assignments and enable access to the API. Copy the application's Client ID and Client Secret.
Copy your Environment ID and Region, which are shown on your environment page in Ping Identity.
During onboarding, provide the following information:
The Client ID and Client Secret of the worker application
Your Environment ID and Region
Pipedrive
Complete the following steps to connect to a Pipedrive API:
Log in to Pipedrive as an administrator and copy the administrator's personal API token.
During onboarding , provide the API token.
Qualtrics
Complete the following steps to enable configuration information access through an administrator account. Your organization must be using Okta as an identity provider. MFA using one-time passcodes must be configured.
Identify the Qualtrics XM administrator whose credentials you will supply to SSPM. The account must have Brand Administrator authority.
To enable SSPM to access the account using Okta credentials:
Identify your Okta subdomain.
Generate and copy and MFA secret key.
Identify your Organization ID. After you log in to Qualtrics XM, your organization ID is included in the Qualtrics XM URL. The URL format is <org-ID>.qualtrics.com.
Identify your SSO display name. To get the display name, go to AdminOrganization> SettingsSSO and open the Edit page for the SSO connection.
During onboarding, provide the information above.
Splunk
Complete the following steps to enable access to configuration information through an administrator account. Your organization must be using Okta as an identity provider. MFA using one-time passcodes must be configured.
Identify the Splunk administrator whose credentials you will supply to SSPM.
To enable SSPM to access the account using Okta credentials:
Identify your Okta subdomain
Generate and copy an MFA secret key
Identify your Splunk app domain, which is a subdomain included in the Splunk Cloud URL. The URL format is <app_domain>.cloud.splunk.com or <app_domain>.splunkcloud.com.
During onboarding, provide your organization's Okta domain, the administrator credentials, the MFA secret key, and the Splunk app domain.
VMware
Complete the following steps to to connect to a VMWare API.
Log in to VMWare Cloud Services using an account that is assigned to the Organization Owner role.
Generate and copy an API token for the organization. Configure the API key to these specifications:
Limit Organization Roles access to the Organization Owner role.
Limit Service Roles to Skyline Advisor.
Select the OpenID scope.
(Optional) Select the email preference option to be notified when the token is about to expire.
Copy your Organization ID, which you can access from your profile.
(Optional) Activate MFA for tokens that are associated with the account, and copy the MFA secret key for the account.
During onboarding, provide the API token and your organization ID. If you configured MFA for tokens, also provide your MFA secret key.
Last updated
Was this helpful?
