What are Connected Apps and what are the key configuration settings an Integration Architect must understand?
Suggested answer
A Connected App is a framework that enables external applications to integrate with Salesforce via OAuth 2.0. Key settings include:
IP Relaxation: Controls whether login IP restrictions are enforced for the Connected App. "Relax IP Restrictions" lets users authenticate from any IP, while "Enforce IP Restrictions" blocks access from outside trusted IP ranges. Over-relaxing creates security risk.
Refresh Token Policy: Controls the lifetime of refresh tokens — can be set to expire immediately, after a defined period, or never. Long-lived refresh tokens increase risk if compromised.
OAuth Scopes: Limit what the Connected App can access (api, refresh_token, web, full, chatter_api, etc.). Follow least-privilege — grant only the scopes required.
Callback URL: The authorized redirect URI for the Web Server flow. Must exactly match what the app sends.
Session Policies: Enforce MFA or specific session security levels for the integration.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.