关于SFDC沙箱连接Azure Data Factory时出现Error code9603未知SOAP错误的排查咨询
Troubleshooting SFDC Sandbox to Azure Data Factory Connection Error 9603
Let's break down targeted solutions for your two questions based on common pitfalls with this error:
1. Additional Salesforce Privileges/Settings to Verify
You've covered the foundational checks (API Enabled, security token reset), but here are other critical areas to inspect:
- Object-level API Access: Even with
API Enabledenabled, the user needs explicit Read/Query API permissions for every object you plan to pull data from in ADF. Navigate to the user's profile →Object Settings, select each target object, and confirm theAPI Accesscheckbox for Read (or relevant operations like Create/Update if needed) is ticked. - IP Range Restrictions: Check if the user's profile or assigned permission sets enforce IP login limits. If ADF's outbound IPs aren't listed in Salesforce's allowed range (found in
Setup→Security Controls→Network Access), the connection will be blocked. You can either add ADF's IPs to the list or assign a permission set that bypasses IP restrictions. - Session Security Requirements: Some orgs enforce strict session rules (e.g., requiring HTTPS, blocking logins from untrusted environments). Verify the user's profile's
Session Settingsto ensure ADF's connection meets these standards. - API Version Compatibility: Confirm the API version selected in your ADF linked service matches an active version in your Salesforce sandbox. Outdated API versions might be disabled, while newer ones could require additional permissions. Check available versions in Salesforce
Setup→API→API Versions. - Permission Set API Permissions: Don't overlook permission sets—many orgs isolate API-related access here instead of profiles. Ensure the user has any permission sets that grant necessary API privileges.
2. How to Diagnose the Exact SOAP Error
The "unknown SOAP response" message is intentionally vague, so use these steps to get concrete details:
- Enable Salesforce Debug Logs:
- In your SFDC sandbox, go to
Setup→Monitoring→Debug Logs. - Create a new trace for the problematic user, set the
APIlog level toDEBUG, and save. - Retest the ADF connection to trigger the error, then check the generated debug log. It will include full SOAP request/response details, including specific permission failures or configuration mismatches.
- In your SFDC sandbox, go to
- Inspect ADF Monitoring Logs:
In Azure Data Factory, navigate toMonitor→Pipeline Runs, find the test connection activity, and view its detailed logs. For deeper insights, enable Diagnostic Settings to send logs to Log Analytics, then run queries to extract specific error details from the connector's output. - Test SOAP API Manually:
Use tools like Postman or SOAP UI to send a direct Salesforce SOAP login request using the same credentials (username + password + security token). If this fails, the API will return a precise error message. If it succeeds, the issue likely lies in ADF's connector configuration (e.g., incorrect API version, missing parameters). - Check Salesforce Login History:
Go toSetup→Monitoring→Login Historyand look for the user's failed login attempts. This will show explicit reasons like "IP address not allowed" or "Invalid credentials" that might not surface in the ADF error.
内容的提问来源于stack exchange,提问作者Valkyrja.Kara
相关产品推荐
相关产品推荐

