From 41c97ad3a30f85ad412dd23d862685c60366076f Mon Sep 17 00:00:00 2001 From: Ronen-Refaeli <119348463+Ronen-Refaeli@users.noreply.github.com> Date: Sun, 17 Aug 2025 14:00:12 +0300 Subject: [PATCH] Update protect-salesforce.md Changes in threat protection support --- CloudAppSecurityDocs/protect-salesforce.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CloudAppSecurityDocs/protect-salesforce.md b/CloudAppSecurityDocs/protect-salesforce.md index 8540e1bc2a..8bf5a260a2 100644 --- a/CloudAppSecurityDocs/protect-salesforce.md +++ b/CloudAppSecurityDocs/protect-salesforce.md @@ -55,7 +55,7 @@ You can use the following built-in policy templates to detect and notify you abo | Type | Name | | ---- | ---- | -| Built-in anomaly detection policy | [Activity from anonymous IP addresses](anomaly-detection-policy.md#activity-from-anonymous-ip-addresses)
[Activity from infrequent country](anomaly-detection-policy.md#activity-from-infrequent-country)
[Activity from suspicious IP addresses](anomaly-detection-policy.md#activity-from-suspicious-ip-addresses)
[Impossible travel](anomaly-detection-policy.md#impossible-travel)
[Activity performed by terminated user](anomaly-detection-policy.md#activity-performed-by-terminated-user) (requires Microsoft Entra ID as IdP)
[Multiple failed login attempts](anomaly-detection-policy.md#multiple-failed-login-attempts)
[Unusual administrative activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual file deletion activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual file share activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual impersonated activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual multiple file download activities](anomaly-detection-policy.md#unusual-activities-by-user) | +| Built-in anomaly detection policy | [Activity from anonymous IP addresses](anomaly-detection-policy.md#activity-from-anonymous-ip-addresses)
[Activity from infrequent country](anomaly-detection-policy.md#activity-from-infrequent-country)
[Activity from suspicious IP addresses](anomaly-detection-policy.md#activity-from-suspicious-ip-addresses)
[Impossible travel](anomaly-detection-policy.md#impossible-travel)
[Activity performed by terminated user](anomaly-detection-policy.md#activity-performed-by-terminated-user) (requires Microsoft Entra ID as IdP)
[Multiple failed login attempts](anomaly-detection-policy.md#multiple-failed-login-attempts)
[Unusual administrative activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual file deletion activities](anomaly-detection-policy.md#unusual-activities-by-user) (Temporarily not supported due to limitation in Salesforce API)
[Unusual file share activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual impersonated activities](anomaly-detection-policy.md#unusual-activities-by-user)
[Unusual multiple file download activities](anomaly-detection-policy.md#unusual-activities-by-user) | | Activity policy template | Logon from a risky IP address
Mass download by a single user| | File policy template | Detect a file shared with an unauthorized domain
Detect a file shared with personal email addresses|