You are on page 1of 26

Catalog Task List Page 1

Report Title: Catalog Task List


Run Date and Time: 02/21/2020 21.39.48 India Standard Time
Run by: Rohit Anand Singh
Table name: sc_task
Query Condition: Active = true AND Assigned To = Rohit Anand Singh (rohit.anand)
Sort Order: Assigned To in ascending order

11 Catalog Tasks

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

TASK0533399 Rohit Anand Process Central 02/19/2020 Open


Singh Provisioning Services 14.38.06
(rohit.anand) for Newly
Created
Security
Group

TASK0534209 Rohit Anand Process New Central 02/20/2020 Open


Singh Admin Services 12.33.46
(rohit.anand) Account
Request

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 2

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

TASK0532840 Rohit Anand Luka Cordasic Process 02/19/2020 Central 02/18/2020 Open
Singh (luka.cordasic) Modify Azure 18.52.53 - Services 19.22.42
(rohit.anand) AD Request Abhishek
Agrawal
(Comments/U
pdates)
Approved

As confirmed
by Yemi.

02/19/2020
16.04.08 -
Rohit Anand
Singh
(Comments/U
pdates)
Security team
: pls go
through mail in
notes and
approve
formally.

02/19/2020
16.03.30 -
Rohit Anand
Singh
(Comments/U
pdates)
From: Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>
Sent:
Wednesday,
February 19,
2020 2:02 PM
To: Anne
Thomas
<Anne.Thoma
s@ihsmarkit.c
om>; Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>; Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>; Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>;
Miguel Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>
Subject: Re:
Salesforce -
Outlook
Integration

Hi everyone,

after detail
inspection of
the

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 3

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

permissions
granted to the
connection
between
Salesforce
and Office 365
we identified
that the
permissions
granted to
Salesforce
are:
1.Sign in and
read user
profile (on
Office 365
Exchange
Online API)
2. Use
Exchange
Web Services
with full
access to all
mailboxes (on
Windows AAD
API)

Infosec has
agreed to
approve this
connection
once we
submit the
request
through
ServiceNow.

Thanks a lot
Yemi and
Steven on
your time and
support in this!

Regards,
Luka

___________
___________
___________
_______
From: Anne
Thomas
<Anne.Thoma
s@ihsmarkit.c
om>
Sent: Monday,
February 17,
2020 12:33
PM
To: Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>; Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>; Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>; Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 4

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

kit.com>;
Miguel Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>
Subject: RE:
Salesforce -
Outlook
Integration

Great,
appreciated.

Kind regards,
Anne

From: Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>
Sent: 17
February 2020
11:20
To: Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>; Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>; Anne
Thomas
<Anne.Thoma
s@ihsmarkit.c
om>; Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>;
Miguel Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>
Subject: RE:
Salesforce -
Outlook
Integration

Hi all,

Just to
confirm,
Stuart, Yemi
and I will have
a meeting on
Tuesday
15:00 GMT to
validate the
permission

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 5

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

levels using
the CDO
tenant.
We will inform
this group on
the results of
our test after
the meeting.

Regards,
Luka

From: Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>
Sent: 14
February 2020
18:25
To: Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>; Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>; Anne
Thomas
<Anne.Thoma
s@ihsmarkit.c
om>; Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>;
Miguel Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>
Subject: RE:
Salesforce -
Outlook
Integration

Yes, I have
GA
permissions in
CDO so let's
test Tuesday
then.

From: Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>
Sent: 14
February 2020
17:19
To: Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>; Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>; Anne

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 6

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

Thomas
<Anne.Thoma
s@ihsmarkit.c
om>; Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>;
Miguel Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>
Subject: RE:
Salesforce -
Outlook
Integration

Hello Stuart,

Thanks for the


update- we
understood
that part
however,
information
security team
is concerned
that the token
might have as
much
permission as
the GA, which
has inherent
risk. We have
had issue with
similar level of
access on
token in the
past, hence
the concern.

I am in
discussion
with CK on
how we can
approach this,
we can test
this using the
CDO tenant.
We need to
see the level
of permission
the token will
have after
integration.

@Stuart
Rodger do you
have GA
permission in
cdo? If so, we
can schedule
a time on
Tuesday with
@Luka
Cordasic
yourself and I.

Thanks,
Yemi.

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 7

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

From: Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>
Sent: Friday,
February 14,
2020 10:54
AM
To: Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>; Anne
Thomas
<Anne.Thoma
s@ihsmarkit.c
om>; Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>; Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>;
Miguel Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>
Subject: RE:
Salesforce -
Outlook
Integration

Hi,

I am finally
catching up
with this email
thread
properly and it
looks like
there's a bit of
a
misunderstand
ing on what is
being
requested.

Salesforce
does not
require the
use of an
account to
connect to our
Azure
AD/O365.
What is does
need during
the initial
configuration
is someone
with
appropriate
permissions
(Global Admin

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 8

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

in this case) to
approve
access into
our AAD/O365
that is
required for it
to work. For
those of you
that have dealt
with App
registrations
previously,
this is the
same as
granting
admin
consent. After
this one-off
task, the GA
account isn't
needed again.
The setup is a
little different
than an app
registration in
that it needs
someone with
GA rights to
enter their
credentials at
one point
before the rest
of the setup
can continue.

So someone
like me or
Rohit can do
this, Luka
doesn't need
permissions
himself and he
doesn't need
another
account.

The question
should be
what
permissions
are we
approving for
Saleforce
once it has
access. We
know it
requires
read/write
access to
calendars and
contacts. But
is this all that
we are
consenting to
as the setup
doesn't
explicitly list
what
permissions
are being
granted. This
is different
from an app
registration as
we can clearly
see what
permissions
are being
asked for (e.g.

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 9

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

read a user
profile in AAD,
write to all
AAD groups).

Stuart

From: Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>
Sent: 14
February 2020
15:15
To: Anne
Thomas
<Anne.Thoma
s@ihsmarkit.c
om>; Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>; Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>; Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>;
Miguel Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>
Subject: RE:
Salesforce -
Outlook
Integration

Hi Anne,

I've opened
the case
already but in
the meantime
Rohit and
Stuart
confirmed that
it is not
possible to
customise
exchange
account roles
in such a way
to have
"specific
permissions".
That is what
the blocker is
here.

On the other
hand
Salesforce
clearly
document why
GA account is
required for

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 10

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

this
connection
and how
Salesforce is
using it.
Salesforce
guarantees
that Microsoft
sets the
breadth of the
scope of
access and
neither
salesforce nor
Microsoft
admins can
adjust it.
Lightning Sync
can only read,
write, and
update
contacts and
events from
users' email
services.
Lightning Sync
isn't designed
to discover or
access other
objects.

https://help.sal
esforce.com/a
rticleView?id=l
ightning_sync
_admin_securi
ty_connection
_oauth.htm&ty
pe=5

REQUIREME
NTWHY IT'S
REQUIREDB
ENEFIT TO
YOU
Lightning Sync
automatically
requests its
scope of
access to all
aspects of
your users'
Exchange
mailbox and
its
resources.Whi
le OAuth 2.0
provides
access to
more objects
in your email
service,
Microsoft sets
the breadth of
that scope.
Neither
Salesforce nor
Microsoft
admins can
adjust it.
However,
Lightning Sync
can only read,
write, and
update
contacts and

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 11

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

events from
users' email
services.
Lightning Sync
isn't designed
to discover or
access other
objects.Minim
al setup is
required to
connect your
applications
using this
method.
This method
provides
access to
users'
Microsoft
contacts and
events without
individual user
authentication.
As a result,
sync between
the
applications
remains
consistent,
and data is
reliably
updated in
both systems
without
dependency
on the user.
Your
company's
Microsoft
admin must
provide
access to your
Microsoft
Office 365
global
administrator
account and
accept access
to Lightning
Sync from
within
Microsoft.After
electing to
connect using
OAuth 2.0,
you're
redirected to a
Microsoft site.
From the
Microsoft site,
you provide
your Office
365
credentials
and accept
Lightning Sync
access to your
Microsoft
account. The
Office 365
admin account
doesn't require
impersonation
rights for your
users, only
global admin
permissions.
Global admin
credentials are

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 12

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

never stored
in Salesforce.
Next, you're
redirected to
the Outlook
Integration
and Sync
page in
Salesforce
Setup, where
your Microsoft
Azure tenant
ID is stored.
Behind the
scenes,
Salesforce
obtains an
access token
to your
Microsoft
account. The
access token
is required to
gain read,
update,
create, or
delete access
to Microsoft
contacts or
events.
Learn More
Working hand-
in-hand with
the
predetermined
scope
requirement,
this method
provides
access to
users'
Microsoft
contacts and
events without
individual user
authentication.
This benefit
provides a
sync
experience
with fewer
interruptions.
Several
measures
provide
security for
your data
during transfer
and within
Salesforce.
•By design,
your Azure
tenant secrets
are never in
transmission
with the OAuth
2.0 connection
method.
Instead,
Salesforce
handles the
management
of both public
and private
keys.
•Your
Microsoft
tenant ID is
encrypted at

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 13

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

rest. It's visible


only from the
Outlook
Integration
and Sync
page, so only
Salesforce
admins (or
other users
with Setup
access) can
see it. Plus,
without signed
Salesforce
verification,
interception of
your tenant ID
can't provide
access to your
Microsoft
account.
•The access
token is
securely
transferred
from your
Microsoft
account to
Salesforce
over a TLS
connection.
The token is
encrypted,
and expires
every hour.
New tokens
are always
transferred
over a TLS
connection.

From: Anne
Thomas
<Anne.Thoma
s@ihsmarkit.c
om>
Sent: Friday,
February 14,
2020 4:03 PM
To: Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>; Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>; Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>; Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>; Miguel
Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Brett

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 14

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

Erickson
<Brett.Erickso
n@ihsmarkit.c
om>
Subject: RE:
Salesforce -
Outlook
Integration

Hi Luka,

I just had
quick chat with
CK,
•Please can
you raise a
case with
Salesforce "to
provide
specific
permission
required in
O365", and
not GA
access.
Include Kam
in Cc so we
can escalate
with Customer
Success
Team.
•CK and team
will make
themselves
available for
any tech calls.

Kind regards,
Anne

From: Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>
Sent: 14
February 2020
14:45
To: Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>; Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>; Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>; Miguel
Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>; Anne
Thomas
<Anne.Thoma
s@ihsmarkit.c
om>
Subject: RE:

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 15

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

Salesforce -
Outlook
Integration

Hello All,

Thanks Rohit
and Stuart on
shedding light
on where
custom role is
at.

Unfortunately,
information
security will
not approve
GA for any
third-party or
vendor
application,
we suggest
you either wait
until exchange
custom role is
GA or look for
another
approach to
sync the
calendar and
contact.

Thanks,
Yemi.

From: Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>
Sent: Friday,
February 14,
2020 5:57 AM
To: Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>; Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>; Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>; Miguel
Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>; Anne
Thomas
<Anne.Thoma
s@ihsmarkit.c
om>
Subject: RE:
Salesforce -
Outlook
Integration

Custom Roles

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 16

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

look like they


are still in
preview at the
moment and,
at this stage,
only certain
permissions
can be
configured.
And this
doesn't
currently
include
anything that
needs to be
used here.

I'm sure that


will change in
the future but
there's no
indication of
timescales in
the
documentation
.

From: Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>
Sent: 14
February 2020
11:11
To: Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>; Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>; Miguel
Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>; Anne
Thomas
<Anne.Thoma
s@ihsmarkit.c
om>
Subject: RE:
Salesforce -
Outlook
Integration

Hi Yemi,

As far as I
know
Currently,
Microsoft has
released
Custom role
permissions

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 17

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

for Application
registrations
only
(microsoft.dire
ctory/applicati
ons.*/* ) . I
tried creating
custom role
for some other
request with
permissions
related to
microsoft.direc
tory/devices/*
through CLI
but it failed.

Also as
Exchange
Administrator
role owner
failed in
integration so I
doubt if only
read/write
permissions
on Contacts/
user's mail
properties will
work.

Regards,
Rohit Anand
Singh
Sr Systems
Administrator |
GTS – Central
Services

From: Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>
Sent: Friday,
February 14,
2020 4:30 PM
To: Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>; Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>;
Miguel Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>; Anne
Thomas
<Anne.Thoma
s@ihsmarkit.c
om>
Subject: RE:
Salesforce -

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 18

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

Outlook
Integration

Hi Yemi,

Rohit and I
had a call to
discuss
custom role
approach in
detail but we
came to a
conclusion
that this would
not work.

We already
tried to
connect to
Exchange
using an
account with
Exchange
admin
permission
which has
R/W on
contacts and
events but that
account did
not work.
(Steve DuBe
from Miguel's
team initially
tried to set-up
the
connection).

I looked for
the detailed
elaboration on
why GA
account is
required and
how
Salesforce is
using it's
permissions
(see below).

As I see it,
question is do
we trust that
our vendor is
using the GA
account as
described in
the official
documentation
.

Please let us
know if this is
enough details
to proceed.

Thank you,
Luka

https://help.sal
esforce.com/a
rticleView?id=l
ightning_sync
_admin_securi
ty_connection
_oauth.htm&ty
pe=5

REQUIREME

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 19

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

NTWHY IT'S
REQUIREDB
ENEFIT TO
YOU
Lightning Sync
automatically
requests its
scope of
access to all
aspects of
your users'
Exchange
mailbox and
its
resources.Whi
le OAuth 2.0
provides
access to
more objects
in your email
service,
Microsoft sets
the breadth of
that scope.
Neither
Salesforce nor
Microsoft
admins can
adjust it.
However,
Lightning Sync
can only read,
write, and
update
contacts and
events from
users' email
services.
Lightning Sync
isn't designed
to discover or
access other
objects.Minim
al setup is
required to
connect your
applications
using this
method.
This method
provides
access to
users'
Microsoft
contacts and
events without
individual user
authentication.
As a result,
sync between
the
applications
remains
consistent,
and data is
reliably
updated in
both systems
without
dependency
on the user.
Your
company's
Microsoft
admin must
provide
access to your
Microsoft
Office 365

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 20

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

global
administrator
account and
accept access
to Lightning
Sync from
within
Microsoft.After
electing to
connect using
OAuth 2.0,
you're
redirected to a
Microsoft site.
From the
Microsoft site,
you provide
your Office
365
credentials
and accept
Lightning Sync
access to your
Microsoft
account. The
Office 365
admin account
doesn't require
impersonation
rights for your
users, only
global admin
permissions.
Global admin
credentials are
never stored
in Salesforce.
Next, you're
redirected to
the Outlook
Integration
and Sync
page in
Salesforce
Setup, where
your Microsoft
Azure tenant
ID is stored.
Behind the
scenes,
Salesforce
obtains an
access token
to your
Microsoft
account. The
access token
is required to
gain read,
update,
create, or
delete access
to Microsoft
contacts or
events.
Learn More
Working hand-
in-hand with
the
predetermined
scope
requirement,
this method
provides
access to
users'
Microsoft
contacts and
events without

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 21

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

individual user
authentication.
This benefit
provides a
sync
experience
with fewer
interruptions.
Several
measures
provide
security for
your data
during transfer
and within
Salesforce.
•By design,
your Azure
tenant secrets
are never in
transmission
with the OAuth
2.0 connection
method.
Instead,
Salesforce
handles the
management
of both public
and private
keys.
•Your
Microsoft
tenant ID is
encrypted at
rest. It's visible
only from the
Outlook
Integration
and Sync
page, so only
Salesforce
admins (or
other users
with Setup
access) can
see it. Plus,
without signed
Salesforce
verification,
interception of
your tenant ID
can't provide
access to your
Microsoft
account.
•The access
token is
securely
transferred
from your
Microsoft
account to
Salesforce
over a TLS
connection.
The token is
encrypted,
and expires
every hour.
New tokens
are always
transferred
over a TLS
connection.

From: Yemi

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 22

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>
Sent:
Thursday,
February 13,
2020 9:35 PM
To: Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>; Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>;
Miguel Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>
Subject: RE:
Salesforce -
Outlook
Integration

Thanks
Miguel.

@Luka
Cordasic I am
thinking we
might be able
to create a
custom role
based on the
requirement,
hence
requesting for
detail
permission
requirements.
If contact role
is included,
then we might
need to grant
the custom
role that
permission.

@Rohit Anand
Singh is this
doable?

Thanks,
Yemi.

From: Luka
Cordasic
<Luka.Cordasi
c@ihsmarkit.c
om>
Sent:
Thursday,
February 13,

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 23

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

2020 1:39 PM
To: Yemi
Olakunori
<Yemi.Olakun
ori@ihsmarkit.
com>; Rohit
Anand Singh
<Rohit.Anand
Singh@ihsmar
kit.com>;
Miguel Zlot
<Miguel.Zlot@
ihsmarkit.com
>
Cc: CK
Johnson
<CK.Johnson
@ihsmarkit.co
m>; Stuart
Rodger
<Stuart.Rodge
r@ihsmarkit.c
om>; Brett
Erickson
<Brett.Erickso
n@ihsmarkit.c
om>
Subject: RE:
Salesforce -
Outlook
Integration

Hi Yemi,

We confirmed
with
Salesforce
that this hybrid
exchange
limitation only
means that it
is not possible
to sync
Salesforce
with both on-
premise and
cloud
exchange at
the same time.
We will only
sync with the
cloud and
salesforce will
fully support
us if we run
into any
issues. We got
this officially
confirmed and
also we
already tested
the connection
on the test
environment.

I can't confirm
that it will
suffice but I
am, of course,
happy to
validate this.
Does
Calendar R/W
also cover
contacts?
Salesforce
sync will
probably
require the

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 24

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

Contact R/W
as well.

Thank you,
Luka

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 25

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

TASK0529428 Rohit Anand Urvi Arya Process 02/13/2020 Central 02/11/2020 Open
Singh (urvi.arya) General 16.42.22 - Services 14.25.42
(rohit.anand) Security Rohit Anand
Group List Singh
Request (Comments/U
pdates)
From: Rohit
Anand Singh
Sent:
Thursday,
February 13,
2020 4:41 PM
To: Rohtash
Kumar
<Rohtash.Ku
mar@ihsmarki
t.com>; Urvi
Arya
<Urvi.Arya@ih
smarkit.com>;
CentralService
s
<centralservic
es@ihsmarkit.
com>
Cc: Nik
Shepherd
<Nik.Shepher
d@ihsmarkit.c
om>; MK-GTS
Production
Support
Windows
<MK-
GTSProductio
nSupportWind
ows@ihsmarki
t.com>
Subject: RE:
Regarding
TASK0529428

Hello Urvi,

We are
working on
migration from
LDAP to
LDAPS for all
services.
Once we
generate
LDAPS
Domain
FQDNs
certificate , we
will inform with
proper
instructions.

Meanwhile if
you could help
us with all
services
where you
might be using
LDAP as
those needs to
switched to
LDAPS
eventually.
Thanks.

Regards,
Rohit Anand
Singh
Sr Systems
Administrator |
GTS – Central

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time
Catalog Task List Page 26

▲ Assigned Requested Short Comments/U Assignment Closed


Number Opened State
To For Description pdates Group Date\Time

Services

TASK0532134 Rohit Anand Vijay Joshi Process 02/17/2020 Central 02/17/2020 Open
Singh (vijay.joshi) Modify 17.49.20 - Services 12.33.36
(rohit.anand) Existing Tanvi Grover
Account (Comments/U
Access pdates)
Request Hi Team, stg
and prd
accounts have
been disabled
except the EP
ones. Also,
kindly remove
all the groups
since we can't
do it.

TASK0527746 Rohit Anand Anthony Smith Process New Central 02/07/2020 Open
Singh (anthony.smith Azure AD Services 00.37.56
(rohit.anand) ) SSO

TASK0532238 Rohit Anand Pradyut Termination - Central 02/17/2020 Open


Singh Kumar Das Deactivate Services 16.25.52
(rohit.anand) (pradyutkumar Accounts
.das)

TASK0534753 Rohit Anand Process Central 02/20/2020 Open


Singh Provisioning Services 21.25.03
(rohit.anand) for Newly
Created
Security
Group

TASK0533403 Rohit Anand Process Central 02/19/2020 Open


Singh Provisioning Services 14.43.37
(rohit.anand) for Newly
Created
Security
Group

TASK0534761 Rohit Anand Process Central 02/20/2020 Open


Singh Provisioning Services 21.33.25
(rohit.anand) for Newly
Created
Security
Group

TASK0534764 Rohit Anand Process Central 02/20/2020 Open


Singh Provisioning Services 21.37.33
(rohit.anand) for Newly
Created
Security
Group

Run by: Rohit Anand Singh 02/21/2020 21.39.48 India Standard Time

You might also like