↳ GitHub sourceConnector
Salesforce Marketing Cloud (via Codeless Connector Framework)
Description
Collects audit events and security events from the Salesforce Marketing Cloud [Audit Trail API](https://developer.salesforce.com/docs/marketing/marketing-cloud/references/mc_rest_audit?meta=Summary). Provides visibility into user activities, system changes, and login events.
- Declared status
- 1
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
Salesforce Marketing Cloud API access
Access to the Salesforce Marketing Cloud API through an Installed Package is required.
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Connect Salesforce Marketing Cloud to Microsoft Sentinel
Follow the [Salesforce Marketing Cloud documentation](https://developer.salesforce.com/docs/marketing/marketing-cloud/guide/install-packages.html) to create an Installed Package with the **Data | Tracking Event | Read** permission scope. Note your tenant-specific REST API and Auth base URLs from the Installed Packages section in Setup.
Manage Salesforce Connections
Add, view, and delete Salesforce connections
Add Connection
Configure API Connection
Base Configuration
Configure your Salesforce API connection
Connection Alias
Enter a unique alias to identify this Salesforce connection. **Important**: Use different aliases for each domain. To update an existing connection, use the same alias or delete and create with the same alias. To replace a connection, delete the old one and create a new one with a new alias.
Query interval (in minutes)
5
10
15
20
30
60
REST API Base URL
Enter your tenant-specific REST API Base URL without trailing slash (Example, https://{subdomain}.rest.marketingcloudapis.com). Find it in the Installed Packages section in Setup.
Auth Base URL
Include your subdomain in the Auth Base URL. This is different from your REST API Base URL.
Data Types
Audit Events - user activities and system changes
Security Events - login attempts and authentication
API Credentials
Configure Installed Package credentials for API access
Select the type of Installed Package you created in Marketing Cloud. **Enhanced Package** uses the OAuth 2.0 client credentials flow against the `/v2/token` endpoint. **Legacy Package** uses the `/v1/requestToken` endpoint. Both require the Consumer Key (Client Id) and Consumer Secret from your Installed Package.
Package Type
Select the Installed Package type and enter its credentials
Package Type
Enhanced Package
Consumer Key
Consumer Secret
Legacy Package
Consumer Key
Consumer Secret
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
SalesforceMktCloudConnector
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC