Connecting the Integration
Snowflake is a cloud data platform that enables secure data storage, processing, and analytics at scale.
Secureframe’s Snowflake integration connects through the Snowflake API to pull user accounts, roles, grants, password policies, alerts, network policies, and key account configuration parameters. This data powers Secureframe’s compliance controls and automated tests to ensure access, password, and account settings remain secure and compliant.
To connect Snowflake with Secureframe, navigate to the Integrations page, select the Native tab, and click + Add native connection. Search for Snowflake, then click Connect. Then follow the steps below:
Create role, user, and OAuth app
In your Snowflake dashboard, open a SQL Worksheet. Copy the provided SQL block from Secureframe and run it using the Run All button.
Important: Before running, replace'password-to-be-replaced'in the script with a strong password. Be sure to keep it in a safe place. This password is only used to complete OAuth consent.
This script will:
1. Create a service user.
2. Assign the correct role and permissions
3. Set up a small warehouse
4. Create an OAuth security integration and print out the OAUTH_CLIENT_ID and OAUTH_CLIENT_SECRETEnter the OAuth Client Secret
From the SQL output, copy the OAUTH_CLIENT_SECRET and paste it into the Secureframe connection form.Enter the OAuth Client ID
From the same SQL output, copy the OAUTH_CLIENT_ID and paste it into the Secureframe connection form.Enter your Snowflake Account URL
Enter the base URL for your Snowflake account. This is the same URL used by other tools (like Tableau, dbt, or an ODBC/JDBC driver) to connect to Snowflake.
Run the following command in Snowflake to get your account locator and region:
SELECT CURRENT_ACCOUNT(), CURRENT_REGION();
Use these values to construct your account URL.
For example:https://<account_locator>.<region>.snowflakecomputing.com
Paste this URL into the Secureframe connection form.Sign in to Snowflake
Click Start Connection.
A Snowflake login window will appear.
1. Enter the username: SECUREFRAME_SERVICE_USER
2. Enter the password you defined in the SQL script
3. Complete the login to grant OAuth access
You can now navigate to the “Integrations” page, and you should be able to see your Snowflake connection.
Permissions, Fields Pulled, Controls, and Automated Tests
Click the provided link or navigate to the “Integration” page.
Select the “Available” tab.
Search for the integration.
Click “View details”.
Important: If Secureframe released a new version of the Snowflake MFA test, accept it under Tests → Go to test activity before the new check runs. Refreshing the old test alone does not apply the update.
Frequently Asked Questions (FAQ)
Why is the Snowflake MFA test failing even though MFA is enabled for active users?
Secureframe released an updated Snowflake MFA test that checks MFA for individual users, not only an account-level authentication policy.
If you still see the older account-level result, open the test, click Go to test activity, and accept the new version. A normal refresh does not switch versions.
After accepting the new version, sync Snowflake and recheck. If it still fails, confirm each in-scope user has MFA enrolled, sync again, and contact Support with a screenshot.
Is there a way to enforce MFA at the Snowflake account level?
Yes. You can still use a Snowflake authentication policy that requires MFA and set it on the account. That remains a strong enforcement pattern in Snowflake.
For the Secureframe MFA test result, make sure you have accepted the current test version under Go to test activity, then sync. The current test evaluates per-user MFA status.
A related Snowflake password policy test is also failing. What should I check?
Missing account-level password policy is a separate gap from MFA. Check with:
SHOW PASSWORD POLICIES;SHOW PASSWORD POLICIES ON ACCOUNT;SHOW PARAMETERS LIKE 'PASSWORD_POLICY' IN ACCOUNT;
If no account-level password policy exists, create and apply one in Snowflake, then re-sync the integration.
