13.1 Activation Targets: Marketing Cloud, External Platforms, Cloud Storage & Data Spaces

Key Takeaways

  • An Activation Target establishes the outbound destination, communication protocol, security credentials, and container structure required to deliver Data Cloud segments and payload attributes.
  • Marketing Cloud Engagement (MCE) targets publish segments directly into automatically generated Shared Data Extensions (Shared DEs) scoped to designated Business Units (BUs), mapping the Unified Individual to Contact Builder's Subscriber Key.
  • Cloud Storage targets (Amazon S3, Google Cloud Storage, Azure Blob Storage, and SFTP) export audience datasets as CSV or JSON files, with configurable GZIP compression, custom folder prefixes, and timestamped subfolder partitioning.
  • External Advertising targets (Google Ads Customer Match, Meta Custom Audiences, Amazon Ads) transmit cryptographically hashed identifiers (SHA-256 for email/phone) and enforce strict platform minimums (such as Google Ads' 1,000 active matched users requirement).
  • Data Spaces enforce multi-brand and departmental isolation by strictly scoping Activation Targets, ensuring users within a specific Data Space can only activate segments to approved, isolated destinations.
Last updated: September 2026

13.1 Activation Targets: Marketing Cloud, External Platforms, Cloud Storage & Data Spaces

Quick Answer: An Activation Target is an administrative entity in Salesforce Data Cloud that defines the destination, authentication credentials, and data delivery specifications for publishing segmented customer audiences. Data Cloud supports four core target categories: Marketing Cloud Engagement (publishing to Shared Data Extensions across Business Units), Cloud File Storage (exporting CSV/JSON files with optional GZIP compression to Amazon S3, Google Cloud Storage, Microsoft Azure Blob, or SFTP), External Advertising Platforms (streaming SHA-256 hashed identifiers to Google Ads, Meta Ads, and Amazon Ads), and Salesforce CRM Core (pushing segments to Sales and Service Cloud). In enterprise multi-brand deployments, Activation Targets are strictly scoped to Data Spaces to prevent cross-brand audience leakage and maintain regulatory compliance.


Architectural Purpose of Activation Targets

Within the Data Cloud end-to-end data lifecycle—Ingest, Harmonize, Unify, Calculate, Segment, and Activate—Activation Targets represent the critical outbound egress bridge. While Segmentation groups unified profiles into distinct cohorts using demographic, behavioral, and calculated criteria, those segments remain latent within the Data Cloud lakehouse until bound to an outbound activation channel.

+-------------------------------------------------------------------------------------------------+
|                                 DATA CLOUD END-TO-END PIPELINE                                  |
+-------------------------------------------------------------------------------------------------+
|  1. INGEST        Batch & Streaming Ingestion (CRM, S3, Web/Mobile SDK, Ingestion API)          |
|        │                                                                                        |
|  2. HARMONIZE     Map Data Lake Objects (DLOs) to Customer 360 Data Model Objects (DMOs)        |
|        │                                                                                        |
|  3. UNIFY         Deterministic & Probabilistic Identity Resolution -> Unified Individual Profile|
|        │                                                                                        |
|  4. CALCULATE     Batch Calculated Insights (LTV, RFM) & Streaming Window Insights              |
|        │                                                                                        |
|  5. SEGMENT       Declarative Segment Canvas -> Final Audience Cohort                           |
|        │                                                                                        |
|  6. ACTIVATE      Activation Definition -> [ ACTIVATION TARGET ] -> Downstream Consumption      |
+-------------------------------------------------------------------------------------------------+

Administrative Separation of Duties

To enforce enterprise security and governance, Salesforce Data Cloud separates the technical configuration of an Activation Target from the operational authoring of an Activation:

  • Data Cloud Architect / Data Cloud Activation Manager: Creates, configures, authenticates, and maintains Activation Targets. This requires configuring OAuth handshakes, AWS IAM role Amazon Resource Names (ARNs), GCP Service Account JSON keys, or SFTP RSA key pairs.
  • Data Cloud Activation Specialist: Consumes existing, pre-authenticated Activation Targets when authoring activations from the Segmentation canvas, with view-only rights on the targets themselves. Business users cannot alter destination credentials, bucket names, or API configurations.

Core Activation Target Types

Consultants must master the unique connection mechanisms, delivery formats, and architectural constraints across all four target types.

+-------------------------------------------------------------------------------------------------+
|                                 CORE ACTIVATION TARGET TYPES                                    |
+-------------------------------------------------------------------------------------------------+
|  1. Marketing Cloud Engagement   --> Shared Data Extensions in Contact Builder (BUs)            |
|  2. Cloud File Storage           --> Amazon S3, Google Cloud Storage, Azure Blob, SFTP          |
|  3. External Ad Platforms        --> Google Ads (Customer Match), Meta (Custom Audiences)       |
|  4. Salesforce Core Platform     --> Sales Cloud & Service Cloud (Standard/Custom Objects)      |
+-------------------------------------------------------------------------------------------------+

1. Marketing Cloud Engagement (MCE)

Marketing Cloud Engagement is the most widely deployed activation target for omni-channel customer journeys, automated email sequences, SMS blasts, and mobile push notifications.

  • Container Destination: When an activation publishes to MCE, Data Cloud automatically creates and populates a Shared Data Extension (Shared DE) within Contact Builder. It does not write to standard user-created data extensions.
  • Business Unit (BU) Provisioning: During target setup, the administrator selects the specific Marketing Cloud Business Units that can access the published audience. Data Cloud places the Shared DE in the top-level parent BU or designated shared folders, enabling child BUs to inherit access based on MCE folder permission rules.
  • Subscriber Key Mapping: A foundational design decision is determining what value populates the MCE Subscriber Key (the primary contact identifier in Contact Builder). Data Cloud allows mapping the Subscriber Key to:
    1. The Unified Individual ID (Salesforce-generated unified profile identifier).
    2. The Contact Point ID (e.g., ContactPointEmailId or ContactPointPhoneId).
    3. An external enterprise identifier via the Party Identification DMO (e.g., legacy CRM Contact ID or ERP Customer Number).

[!IMPORTANT] Consultant Trap: Subscriber Key Inflation in Marketing Cloud. If you map the Unified Individual ID as the Subscriber Key into Marketing Cloud Engagement, but your existing MCE org already contains 5 million Contacts identified by standard Salesforce CRM 003 Contact IDs, MCE will treat the incoming Unified Individual IDs as net-new contacts. This duplicates your Contact Builder billable contact count and severs historical tracking data. Always align your Data Cloud Subscriber Key mapping with the legacy MCE Contact Builder subscriber model!

2. Cloud File Storage Targets (S3, GCS, Azure Blob, SFTP)

For downstream data warehouses, enterprise data lakes, third-party email service providers (ESPs), call center dialers, and direct mail fulfillment vendors, Data Cloud supports file-based exports to cloud object storage.

  • Supported Endpoints:
    • Amazon Web Services (AWS) S3: Configured using IAM Role ARN authentication (Salesforce assumes an external AWS role via trusted tenant handshake) or direct S3 Access Keys.
    • Google Cloud Platform (GCS): Authenticated using GCP Service Account private key JSON credentials with Storage Object Admin permissions.
    • Microsoft Azure Blob Storage: Authenticated via Shared Access Signature (SAS) tokens or storage account keys.
    • Secure File Transfer Protocol (SFTP): Authenticated via username/password or SSH private key authentication.
  • Export Formatting & Compression: Data is written as delimited CSV or structured JSON files. Administrators can enable GZIP compression to drastically reduce egress bandwidth and cloud storage costs.
  • Directory Structure & Partitioning: Data Cloud exports files into an automated hierarchical folder structure based on the target configuration: /<TargetDirectory>/<SegmentDeveloperName>/YYYY/MM/DD/hh/<ActivationName>_<Timestamp>.<format>
  • Manifest Metadata File: Accompanying each data export is a JSON metadata manifest file (e.g., manifest.json) containing export timestamps, record counts, schema field names, data types, and segment identifiers. Downstream ETL tools (e.g., AWS Glue, Apache Airflow) use this manifest to validate ingestion completeness before loading.

3. External Advertising Platforms (Google Ads, Meta, Amazon Ads)

Data Cloud provides native connectors to activate first-party audiences directly into digital advertising ecosystems for lookalike modeling, campaign suppression, and retargeting.

  • Google Ads (Customer Match): Transmits audience identifiers to Google Ads accounts via the Google Ads API. Google requires authenticated OAuth linking between Data Cloud and the Google Ads Manager Account (MCC). Identifiers include email addresses, phone numbers, postal addresses, and mobile device IDs.
  • Meta Ads (Custom Audiences): Connects to Meta Business Manager and specific Ad Account IDs. Publishes audiences directly into Meta's Custom Audience container for targeting across Facebook, Instagram, and Audience Network.
  • Cryptographic PII Hashing (SHA-256): Privacy regulations and platform API policies strictly prohibit transmitting cleartext PII to ad networks. Data Cloud automatically normalizes (lowercasing, trimming leading/trailing whitespace, formatting phone numbers to E.164) and applies SHA-256 cryptographic hashing to email and phone attributes before network transmission.
  • Minimum Active Match Thresholds: External platforms enforce minimum audience sizes before serving ads to preserve consumer privacy:
    • Google Ads Customer Match: Requires a minimum of 1,000 active matched users across Google Search, YouTube, or Gmail. If an activation publishes 800 users, or if only 750 of 1,500 submitted records match Google accounts, the campaign status remains "List size too small" and will not deliver ads.
    • Meta Custom Audiences: Recommends at least 1,000 active matched profiles, though smaller audiences may enter the account in a paused state.

4. Salesforce Core Platform Targets (Sales & Service Cloud)

Organizations frequently need to operationalize Data Cloud segments directly inside core CRM workflows:

  • Pushing high-intent B2B prospect segments to Sales Cloud as Campaign Members or Cadence targets.
  • Activating churn-risk customer segments into Service Cloud to trigger proactive outreach tasks for account managers.
  • Audiences are delivered either via native CRM Activation Targets or through Data Actions that emit Platform Events into the core Salesforce bus.

Data Spaces and Activation Targets

In enterprise architectures, multiple subsidiaries, business lines, or geographic regions often share a single Data Cloud instance (e.g., a conglomerate operating Luxury Hospitality and Budget Travel brands).

+-------------------------------------------------------------------------------------------------+
|                                 DATA SPACES MULTI-BRAND TOPOLOGY                                |
+-------------------------------------------------------------------------------------------------+
|                                     SALESFORCE DATA CLOUD INSTANCE                              |
|                                                                                                 |
|   ┌──────────────────────────────────────────────┐ ┌──────────────────────────────────────────┐   |
|   │       DATA SPACE: "LUXURY_BRANDS"            │ │       DATA SPACE: "BUDGET_TRAVEL"        │   |
|   │                                              │ │                                          │   |
|   │ - DMOs: Harmonized Luxury Guests             │ │ - DMOs: Harmonized Economy Travelers    │   |
|   │ - Segments: High-Net-Worth Travelers         │ │ - Segments: Discount Flight Seekers      │   |
|   │ - Activation Targets:                        │ │ - Activation Targets:                    │   |
|   │   1. MCE Luxury BU (Shared DE)               │ │   1. MCE Economy BU (Shared DE)          │   |
|   │   2. Luxury AWS S3 Bucket                    │ │   2. Budget Travel SFTP Server           │   |
|   │   3. Luxury Meta Ad Account                  │ │   3. Budget Google Ads Account           │   |
|   └──────────────────────┬───────────────────────┘ └────────────────────┬─────────────────────┘   |
|                          ▼                                              ▼                         |
|             [ MCE Luxury BU Shared DE ]                    [ MCE Economy BU Shared DE ]           |
|             (Strict Brand Isolation)                       (Strict Brand Isolation)               |
+-------------------------------------------------------------------------------------------------+

Architectural Rules for Data Space Scoping:

  1. Target Assignment upon Creation: When creating an Activation Target, the administrator must assign it to a specific Data Space (or the default Data Space). Once assigned and saved, an Activation Target's Data Space cannot be modified.
  2. Strict Segmentation Isolation: A Segment authored within the Luxury_Brands Data Space can only be activated to Activation Targets provisioned within the Luxury_Brands Data Space. It cannot target an S3 bucket or Marketing Cloud BU belonging to Budget_Travel.
  3. Cross-Brand Leakage Prevention: Data Spaces eliminate compliance violations by ensuring sensitive customer attributes (such as VIP spending tier or medical dietary preferences collected by one brand) cannot be inadvertently exported to a partner brand's advertising account or communication channels.

Architectural Comparison: Activation Target Categories

Technical DimensionMarketing Cloud EngagementCloud Object Storage (S3/GCS/Blob)External Ad Platforms (Google/Meta)Salesforce Core Platform
Destination ContainerShared Data Extension (Contact Builder)File object in cloud bucket / SFTP directoryPlatform Custom Audience / Customer Match ListCore CRM Object (e.g., Campaign Member)
Authentication MethodNative Salesforce MC Connector OAuthAWS IAM Role ARN / GCS JSON Key / Azure SAS / SSH KeyOAuth 2.0 App Handshake / Ad Account AuthorizationNative Salesforce Connected App / Named Credential
Supported FormatsRelational Database FieldsDelimited CSV or structured JSON (optional GZIP)Direct API Payload (Normalized & SHA-256 Hashed)Standard/Custom Salesforce SObject Fields
Primary IdentifierSubscriber Key (Unified ID, Contact Point ID, Party ID)Configurable Unique Key (Unified Individual ID)Hashed Email, Hashed Phone, Mobile Ad ID (IDFA/GAID)Salesforce 18-character Record ID (Contact/Lead ID)
Refresh ModesIncremental (Add/Update) and Full RefreshIncremental (Delta file) and Full Refresh (Snapshot)Incremental list synchronizationIncremental record upsert / Flow trigger
Downstream LatencyNear-real-time to scheduled batch (minutes)Scheduled batch (file write completion)Ad platform processing delay (6 to 48 hours)Near-real-time (Flow / Platform Event)

Consultant Decision Framework & Exam Traps

  • Exam Trap: Activating Segments directly to Marketing Cloud Journey Builder. Data Cloud does not inject segment members directly into an active Journey Builder canvas execution line. It activates audiences into a Shared Data Extension. To enter those customers into a Journey, the Marketing Cloud specialist must configure a Journey using a Data Cloud Audience Entry Event or a scheduled Data Extension entry source linked to that Shared DE.
  • Exam Trap: Changing Activation Target Data Space after Deployment. Once an Activation Target is created inside a Data Space, its Data Space binding is permanent. If an organization restructures its Data Space architecture, new Activation Targets must be provisioned and existing Activations recreated.
  • Exam Trap: Assuming Ad Platforms Instantly Serve Ads. When Data Cloud marks a Google Ads activation status as Success, it confirms successful API receipt. Google Ads requires an additional 24 to 48 hours to hash-match incoming identifiers against Google accounts and evaluate the 1,000 active user threshold. Do not declare an ad activation failed if ads do not serve within the first hour.
Loading diagram...
Data Cloud Outbound Activation Architecture across Target Categories
Test Your Knowledge

A multinational enterprise uses Marketing Cloud Engagement (MCE) with ten regional Business Units (BUs). The central marketing operations team configures an Activation Target in Salesforce Data Cloud to deliver a unified customer audience to three European BUs. Where does Data Cloud store the published audience records inside Marketing Cloud Engagement, and how are contacts identified?

A
B
C
D
Test Your Knowledge

A lead data architect is configuring an Activation Target to export audience segments to an Amazon Web Services (AWS) S3 bucket for consumption by an on-premises enterprise data warehouse. Which security credential configuration represents the Salesforce-recommended best practice for authenticating to the AWS S3 bucket, and how does Data Cloud structure the exported files?

A
B
C
D
Test Your Knowledge

A retail conglomerate manages two distinct brands—'AeroFootwear' and 'LuxeApparel'—within a single Salesforce Data Cloud tenant. The enterprise implements Data Spaces to ensure complete brand separation. A marketing specialist working in the AeroFootwear Data Space creates a high-churn segment and attempts to activate it to an S3 bucket configured for LuxeApparel. What prevents this activation, and how is governance enforced?

A
B
C
D