Skip to main content

We are not on OAuth 2.0 but on a Service Account which will not be supported as soon as we move from EWS to Graph and we plan to move in next week and before that move away from Service Account to OAuth 2.0. What will be my steps to perform once I move from service Account 2.0 to OAuth 2.0 to retain Lightning Sync until its potential end of life on Graph? 

 

#Outlook Lightning Sync

1 件の回答
  1. 8月27日 16:22

    Hey Irfan, 

     

    Important context before the steps: per Salesforce's own release note, Salesforce doesn't recommend trying to keep Lightning Sync alive on Graph long-term, it retires Lightning Sync overall by April 2027 regardless of auth method, they explicitly say either move to Graph, or plan to move from Lightning Sync to Einstein Activity Capture, and recommend contacting Salesforce Customer Support to evaluate options for the Graph connection since it's beta. So if this is a long-term client, factor EAC into your roadmap even if Graph buys you short-term breathing room. 

     

    That said, for your immediate ask (Service Account → OAuth 2.0, staying on Lightning Sync short-term before the Graph cutover): 

     

    1. In Azure/Entra ID, register an app (or confirm your existing Salesforce-Microsoft app registration) with the correct Graph/EWS API permissions, since you're moving away from the Service Account model, you'll set up org-wide OAuth 2.0 delegated or application permissions instead of a static service account credential. 

    2. In Salesforce, go to Setup > Outlook Integration and Sync Reminders (or Lightning Sync setup), switch your connection method from Service Account to OAuth 2.0, this reconfigures how Salesforce authenticates to Microsoft going forward. 

    3. Re-authenticate/re-authorize the connection using an admin account through the OAuth consent flow, this replaces the static service account token with a proper delegated OAuth grant. 

    4. Test with a small pilot group before rolling to your full user base, confirm sync (contacts/calendar/events) still functions correctly under the new auth method before the Graph migration next week. 

    5. Once OAuth 2.0 is confirmed stable, proceed with your planned EWS-to-Graph migration, per Salesforce's release note, this requires coordinating with your Microsoft Global Admin to enable Graph on the Microsoft side, and Salesforce Support involvement since the Graph connection for Lightning Sync is currently in beta. 

     

    Given the beta status and the retirement timeline, I'd genuinely recommend contacting Salesforce Support directly before completing the OAuth migration, since they can confirm what's officially supported for Lightning Sync + Graph in your specific org right now, this isn't a fully mature, self-service path yet. 

     

    Reference:

    https://help.salesforce.com/s/articleView?id=release-notes.rn_sales_productivity_ls_update_from_ews.htm&language=en_US&type=5

0/9000