Varonis Enhances Salesforce Security With High-Risk Permissions Remediation

Automatically identify and remediate high-risk Salesforce permissions to improve your SaaS security posture with Varonis.
Nathan Coppinger
2 min read
Last updated September 17, 2024
High risk permissions remediation in Salesforce

Today, we’re excited to announce new Salesforce remediation features that help organizations proactively find and revoke high-risk user permissions.

Unlike other SSPM solutions that merely identify problems, Varonis pinpoints where sensitive data is at risk and addresses issues at scale through automation. The new remediation capabilities enable Salesforce admins and security teams to:

  • Prevent users from exporting reports
  • Find and eliminate passwords that never expire
  • Control third-party API connections
  • Ensure users can only see data they're meant to see

In this blog, we’ll outline our new updates to Varonis for Salesforce. If you happen to be at Dreamforce this week, stop by booth #1320 for a live demo! 

Proactively identify users with high-risk permissions.

To ensure organizations have a real-time understanding of Salesforce permissions and the data they could expose, Varonis automatically generates a report of profiles and permission sets that allow users to perform high-risk actions such as: 

  • Export reports
  • Create public links
  • Generate passwords that never expire
  • Manage authentication provider connections to Salesforce
  • Share report owner viewing permissions with other users

This report also shows the users assigned these permissions, their activity status, and the sensitive data exposed to risk. This holistic view of permissions empowers security teams and Salesforce admins to limit access to critical data and enforce least privilege.

Automatically surface entitlements with high-risk permissions.

Salesforce risky permissions widget

Automatically surface entitlements with high-risk permissions.

Automatically generate a report of users assigned high-risk permissions.

Risky permissions report

Automatically generate a report of users assigned high-risk permissions.

Revoke risky permissions and enforce least privilege.

Varonis goes beyond analyzing and reporting on Salesforce permissions. With Varonis for Salesforce, admins can revoke the risky entitlements at scale with just a few clicks.

Salesforce admins simply select the desired permissions, navigate to “run action,” select “remove permission,” and click “save.” Varonis automatically revokes the permissions from every selected profile and permission set and commits the changes directly to Salesforce.

Automatically revoke high-risk permissions — like the ability to export reports — from users and entitlements.

Revoke export report permission

Automatically revoke high-risk permissions — like the ability to export reports — from users and entitlements.

Reduce Salesforce data risk at scale.

Varonis’ new capabilities to locate and remove risky permissions in Salesforce add to our already robust remediation features that help organizations secure their data. With Varonis for Salesforce, security teams and Salesforce admins can:

Automatically remediate data exposure risks in Salesforce and get to a least privilege model.

Remediate links

Automatically remediate data exposure risks in Salesforce and get to a least privilege model.

Try Varonis for free.

Available on the Salesforce AppExchange, Varonis for Salesforce helps security teams continuously monitor and improve their Salesforce security posture in real time.

Request a demo today and visit us at Dreamforce, booth #1320, to see our solution in action.

What should I do now?

Below are three ways you can continue your journey to reduce data risk at your company:

1

Schedule a demo with us to see Varonis in action. We'll personalize the session to your org's data security needs and answer any questions.

2

See a sample of our Data Risk Assessment and learn the risks that could be lingering in your environment. Varonis' DRA is completely free and offers a clear path to automated remediation.

3

Follow us on LinkedIn, YouTube, and X (Twitter) for bite-sized insights on all things data security, including DSPM, threat detection, AI security, and more.

Try Varonis free.

Get a detailed data risk report based on your company’s data.
Deploys in minutes.

Keep reading

Varonis tackles hundreds of use cases, making it the ultimate platform to stop data breaches and ensure compliance.

protecting-salesforce:-remediating-misconfigured-sites
Protecting Salesforce: Remediating Misconfigured Sites
Varonis enables organizations to identify and remediate misconfigured Salesforce Site guest permissions that expose sensitive data publicly.
how-varonis'-approach-to-sspm-helps-your-company
How Varonis' Approach to SSPM Helps Your Company
Adopt a data-first approach with Varonis' SSPM, securing SaaS apps and reducing risk. Learn how you can get better visibility, automation, and protection.
protecting-salesforce:-preventing-public-link-creation
Protecting Salesforce: Preventing Public Link Creation
Identify and prevent the creation of Salesforce public links and reduce your blast radius with Varonis.
automate-exchange-distribution-list-management
Automate Exchange Distribution List Management
From a business perspective, distribution lists (DLs) for email communications are a powerful and well-understood concept in IT. And they are popular: Exchange admins have voted with their right-clicks, creating...