SaaS Security
Onboard an Intercom App to SSPM
Table of Contents
Expand All
|
Collapse All
SaaS Security Docs
Onboard an Intercom App to SSPM
Onboard an Intercom app to SSPM to detect posture risks.
Where Can I Use This? | What Do I Need? |
---|---|
|
Or any of the following licenses that include the Data Security license:
|
To run scans of your Intercom instance, SSPM connects to the Intercom instance by
using information that you provide. Once SSPM connects, it scans the Intercom
instance and will continue to run scans at regular intervals.
Onboard an Intercom App to SSPM Using an Access Token
Onboard an Intercom app to SSPM to detect posture and account risks.
For SSPM to detect posture risks in your Intercom instance, you must onboard your
Intercom instance to SSPM. Through the onboarding process, SSPM connects to an
Intercom API by using an access token that you generate from the Intercom Developer
Hub. After connecting to the Intercom API, SSPM scans your Intercom instance for
misconfigured settings and account risks.
To access your Intercom instance, SSPM requires the following information, which you
will specify during the onboarding process.
Item | Description |
---|---|
Access Token |
A unique, alphanumeric string that Intercom generates for an
Intercom application that you create. The access token has the
permissions that you specify in the Intercom application.
|
Region |
The region where Intercom is hosting your data.
|
To onboard your Intercom instance, you complete the following actions:
- Generate and copy an access token.To generate the access token, you need to create an app in Intercom's Developer Hub.
- Identify the Intercom account that you will use to create the Intercom app.Required Permissions: To create the Intercom app, the account must be assigned to a role that has the Apps and Integrations Access permissions. This could be a custom Developer role or a role with greater permissions.Open a web browser to the Intercom login page and log in to the account you identified.Navigate to Intercom's Developer Hub.
- Click the settings icon (gear icon) in the lower-left corner of the window.
- From the Settings navigation pane, select IntegrationsDeveloper Hub.The Your apps page lists any Intercom apps that you have created. From here, you can create an app.
On the Your apps page, click New app.In the New app dialog, complete the following actions:- Specify an App Name. Your app will be listed in the Developer Hub with other apps, so give it a meaningful name, such as SSPM Integration Token.
- Select the Workspace where you want to add the app.
- Create app.Intercom displays a configuration page for the new app.
By default, your app has permission to all the data in your workspace. Edit your app to limit its permissions to the minimum permissions that SSPM requires.- On the configuration page, make sure the Authentication tab is selected.
- On the Authentication page, click Edit.
- In the Workspace data area, deselect all the check boxes except for the Read admins check box.
Regenerate your access token.Although Intercom created an access token when you created your app, Intercom created this token before you modified the app's permissions. You must regenerate the token for the permission updates to take effect.- In the left navigation pane, select Test and publish Your workspaces.
- On the Your workspaces page, locate the access token and
Regenerate token.
- A confirmation dialog warns you that regenerating the token will delete the current token. Confirm that you want to Regenerate the token.
- On the Your workspaces page, copy the access token and paste it
into a text file.Don’t continue to the next step unless you have copied the access token. You must provide this token to SSPM during the onboarding process.
Identify your Intercom region.Use the following table to determine, based on your login URL, the region where Intercom is hosting your data.URL Region https://app.intercom.com US (United States) https://app.eu.intercom.com EU (European Union) https://app.au.intercom.com AU (Australia) Connect SSPM to your Intercom instance.In SSPM, complete the following steps to enable SSPM to connect to your Intercom instance.- Log in to Strata Cloud Manager.Select ManageConfigurationSaaS SecurityPosture SecurityApplicationsAdd Application and click the Intercom tile.On the Posture Security tab, Add New instance.Log in with Credentials.Enter your access token and region.Connect.