diff --git a/CloudAppSecurityDocs/protect-salesforce.md b/CloudAppSecurityDocs/protect-salesforce.md index 8540e1bc2a..8bf5a260a2 100644 --- a/CloudAppSecurityDocs/protect-salesforce.md +++ b/CloudAppSecurityDocs/protect-salesforce.md @@ -55,7 +55,7 @@ You can use the following built-in policy templates to detect and notify you abo | Type | Name | | ---- | ---- | -| Built-in anomaly detection policy | [Activity from anonymous IP addresses](anomaly-detection-policy.md#activity-from-anonymous-ip-addresses)
[Activity from infrequent country](anomaly-detection-policy.md#activity-from-infrequent-country)
[Activity from suspicious IP addresses](anomaly-detection-policy.md#activity-from-suspicious-ip-addresses)
[Impossible travel](anomaly-detection-policy.md#impossible-travel)
[Activity performed by terminated user](anomaly-detection-policy.md#activity-performed-by-terminated-user) (requires Microsoft Entra ID as IdP)
[Multiple failed login attempts](anomaly-detection-policy.md#multiple-failed-login-attempts)
[Unusual administrative activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual file deletion activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual file share activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual impersonated activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual multiple file download activities](anomaly-detection-policy.md#unusual-activities-by-user) | +| Built-in anomaly detection policy | [Activity from anonymous IP addresses](anomaly-detection-policy.md#activity-from-anonymous-ip-addresses)
[Activity from infrequent country](anomaly-detection-policy.md#activity-from-infrequent-country)
[Activity from suspicious IP addresses](anomaly-detection-policy.md#activity-from-suspicious-ip-addresses)
[Impossible travel](anomaly-detection-policy.md#impossible-travel)
[Activity performed by terminated user](anomaly-detection-policy.md#activity-performed-by-terminated-user) (requires Microsoft Entra ID as IdP)
[Multiple failed login attempts](anomaly-detection-policy.md#multiple-failed-login-attempts)
[Unusual administrative activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual file deletion activities](anomaly-detection-policy.md#unusual-activities-by-user) (Temporarily not supported due to limitation in Salesforce API)
[Unusual file share activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual impersonated activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual multiple file download activities](anomaly-detection-policy.md#unusual-activities-by-user) | | Activity policy template | Logon from a risky IP address
Mass download by a single user| | File policy template | Detect a file shared with an unauthorized domain
Detect a file shared with personal email addresses|