Loading
Prepare for Email to Become the Default Login ExperienceRead More
Ongoing maintenance for Salesforce HelpRead More
Secure Your Salesforce Org
Configure OAuth Policies: Manage External Client App OAuth Credentials with AWS Secrets Manager Control

Configure OAuth Policies: Manage External Client App OAuth Credentials with AWS Secrets Manager Control

This security integration enables Salesforce to automatically synchronize and store External Client App OAuth consumer secrets directly within a centralized AWS Secrets Manager vault.

Control Name

External Client Apps: Configure OAuth Policies: Manage External Client App OAuth Credentials with AWS Secrets Manager

Recommended Configuration

Manage External Client App OAuth Credentials with AWS Secrets Manager.

Control Overview

This security integration enables Salesforce to automatically synchronize and store External Client App OAuth consumer secrets directly within a centralized AWS Secrets Manager vault rather than maintaining them as static metadata within the Salesforce platform.

Security Risk If Not Configured

Weak external management or decentralized storage of OAuth secrets leads to a single-point breach risk where a compromise of unsecured credentials exposes all integrated backend services to unauthorized access.

Threat Scenarios

An attacker gains access to a plaintext configuration file or an unprotected administrative interface containing static secrets and uses those credentials to impersonate the external client application across multiple production environments.

Estimated CVSS Score Range

High (7.0–8.9).

Risk Impact Considerations

Failure to use a hardware-backed or managed vault results in persistent credential exposure, as compromised secrets often remain valid for extended periods without the benefit of automated rotation or centralized audit logging.

Higher Risk When

When the same OAuth secret is manually shared across multiple distributed cloud environments or stored in version control systems without cryptographic protection.

Low Risk When

If the company already uses a robust, identity-based access management policy within AWS that restricts secret retrieval to specific verified VPC endpoints and execution roles.

Business and Integration Considerations

Implementing this control requires an active AWS account and the configuration of a named credential in Salesforce to establish a secure mutual authentication path between the two cloud platforms.

Recommended Remediation

Configure the External Client App to use AWS Secrets Manager for credential storage by defining the secret Amazon Resource Name and establishing the necessary cross-cloud authorization policies.

Security Health Review Guidance

Security Health Review identifies the use of externalized secret management as a strongly recommended standard for high-assurance integrations to make sure that sensitive authentication artifacts are protected by enterprise-grade vaulting and automated rotation policies.

 
Loading
Salesforce Help | Article