Loading

Einstein Activity Capture: User-Level Microsoft Exchange Connections Require Individual Reconnection After OAuth Token Expiration

Julkaisupäivä: Aug 4, 2026
Kuvaus

When Einstein Activity Capture is configured using user-level authentication, each user's connection to their Microsoft Exchange or Office 365 account is established using their own individual OAuth credentials. EAC periodically refreshes these tokens in the background to maintain continuous sync of emails and calendar events.

If Microsoft Azure Active Directory invalidates or fails to renew an OAuth access token — due to any unexpected reasons such as a password change, a multi-factor authentication (MFA) update, an expired refresh token, or a change in Azure AD conditional access policies — EAC loses the ability to sync that user's data and can mark the connected account as "Needs Attention."

Users may see one or more of the following error messages:

• "Something went wrong. Contact Salesforce Customer Support for help."
• "We can't authorize the connected account. Make sure the user has the required permissions. Or reconnect the account and try again."
• "Your service account can't access your users' connected accounts. Give the service account the impersonation role and required permissions, then try again."

 

Because this uses user-level authentication, each OAuth token belongs exclusively to that individual user. Salesforce does not hold administrator-level credentials and cannot re-authenticate on behalf of users. There is no bulk reconnect or admin-initiated reconnect option for user-level connections. Each affected user must reconnect their account individually. This is expected, working-as-documented behavior.

Ratkaisu

Each affected user must reconnect their individual connected account from their personal Salesforce settings. This re-initiates the OAuth authorization flow with Microsoft and restores EAC's ability to sync emails and calendar events.

If a large number of users are affected and individual reconnection is not practical, consider evaluating whether org-level (service account) authentication is suitable for your organization. With org-level authentication, a single service account authorizes access for all users, eliminating the need for individual re-authentication when tokens expire. Note that switching authentication types requires reconfiguration by a Salesforce administrator.

If users continue to see "Needs Attention" after reconnecting, work with your IT or Microsoft Azure AD administrator to determine whether conditional access policies, token lifetime settings, or service account permission changes are preventing OAuth token refresh on the Microsoft side.

Each affected user should follow these steps to reconnect their Einstein Activity Capture connected account:

From Personal Setting

  1. Select "Email and Calendar Account"
  2. Select "Connected Account"
  3. Click on "Reconnect"
Lisäresurssit
Knowledge-artikkelin numero

005390585

 
Ladataan
Salesforce Help | Article