You are here:
Authentication FAQs
Answers to your questions about Marketing Cloud Connect for Marketing Cloud Engagement authentication, including Connected Apps and OAuth 2.0.
How Do We Authenticate Between the Clouds?
Marketing Cloud Connect uses Connected App and OAuth 2.0, trusted authentication tools. These tools allow you to work seamlessly across Sales Cloud, Service Cloud, and Engagement without the need to store credentials. Connected App authenticates users from Engagement into Sales and Service Clouds. OAuth 2.0 authenticates users from Sales and Service Clouds into Engagement.
What Are Connected Apps?
Connected Apps are Salesforce managed packages used to connect applications to Salesforce using APIs.
What Are the Benefits of Connected App Authentication?
Connected App authentication is a secure connection and authentication mechanism between Sales Cloud, Service Cloud, and Engagement. Connected App doesn’t require you to store Sales or Service Cloud passwords in Engagement. It also prevents SOAP and REST API calls made by Marketing Cloud Connect from counting against your rolling 24-hour limit.
Does Connected App Authentication Remove All API Limits?
No. Connected App Authentication only excludes SOAP, REST, and BULK API calls made by Marketing Cloud Connect. Concurrent API request limits are still enforced. Most calls made by Marketing Cloud Connect are SOAP and REST. BULK API calls are only used by Synchronized Data Extension Refresh when the feature is enabled.
Is Connected App Authentication Required?
Yes. As of June 1, 2016, all Marketing Cloud Connect customers are required to use Connected App Authentication.
Can I Send to CRM Audiences While Upgrading to Connected App Authentication?
No. The connection between Sales Cloud, Service Cloud, and Marketing Cloud Engagement is broken during the upgrade process, so ensure that all Marketing Cloud Connect activities are paused. All sends to reports, campaigns, contacts, leads, and Salesforce data extensions fail. Marketing Cloud Engagement sends that don’t involve Marketing Cloud Connect aren’t affected. We suggest scheduling a 1–2 hour outage depending on your number of connected users.
Can I Send to Traditional Engagement Audiences While Upgrading My Account Authentication?
Yes. Normal Engagement sends continue to work.
Can Connected App Authentication Be Rolled Back After It’s Enabled?
No. After you authenticate using Connected App Authentication, you can’t revert to legacy authentication.
What Is OAuth 2.0?
OAuth 2.0 Authentication uses access tokens to provide a secure connection between the clouds, without storing any Engagement user passwords in Sales and Service Clouds.
When Is OAuth Implemented? Will the User Experience Change?
This enhanced authentication is available starting with the 208.1 managed package release. After upgrading, existing Marketing Cloud Connect users are prompted to reenter their Marketing Cloud Engagement credentials the next time they access Marketing Cloud Connect. The rest of the user experience remains the same.
Is OAuth 2.0 Authentication Required?
Yes. All accounts that are upgraded to the 208.1 managed package or newer use OAuth 2.0.
How Do I Download and Complete This Update?
To reduce downtime or impact to your business, follow these steps if you’re upgrading from an older version of the managed package:
- To understand feature changes in the 208.1 managed package, review the latest releases page.
- To minimize downtime if an unexpected error occurs, schedule the upgrade during off-peak hours.
- Allow all scheduled sends to complete before starting the upgrade, if possible.
- Ensure that you can log in to Engagement using the current API user credentials.
- Follow the steps on the Install Managed Package page.
After upgrading, existing Marketing Cloud Connect users are prompted to reenter their Engagement credentials the next time they access Marketing Cloud Connect.
- Verify that Marketing Cloud Connect API user credentials migrated after upgrading by navigating to the Marketing Cloud tab in Sales or Service Cloud.
How Can I Verify That Marketing Cloud Connect API User Credentials Migrated After Upgrading to OAuth 2.0?
If the user didn’t migrate, non-Enterprise 2.0 accounts are prompted to enter Marketing Cloud Connect API user credentials. Enterprise 2.0 accounts follow these steps to confirm:
- In Sales or Service Cloud, navigate to the Marketing Cloud tab.
- Click Configure Marketing Cloud Connector.
- Click Manage Business Units.
- Confirm that previously active Business Units are still active.
- If Marketing Cloud Connect API user credentials didn’t migrate, click Change API User from the configuration page.
- Enter the Marketing Cloud Connect API user credentials and save.
- Click Manage Business Units.
- Confirm that previously active Business Units are now active.
