Question

Difficulty: MediumSession Settings and Password Policies

A Salesforce administrator is instructed to enforce strict security controls specifically for users assigned to the Call Center Representative profile. Internal compliance requires that call center representatives experience an inactivity timeout after 30 minutes of idle time and be required to change their passwords every 60 days. These requirements must override the default organization-wide settings without impacting other profiles. Which TWO actions must the administrator take to fulfill these requirements?

  1. Adjust the Session Settings section directly on the Call Center Representative profile to set the session timeout to 30 minutes.Answer
  2. Modify the Password Policies settings directly on the Call Center Representative profile to enforce password expiration every 60 days.Answer
  3. C
    Create a permission set specifying the 30-minute session timeout and 60-day expiration rules and assign it to the call center representatives.
  4. D
    Add the call center IP address range to the Network Access setup page to automatically enforce shorter session lifetimes.

Answer

To enforce specific session inactivity limits and password expiration rules for a targeted set of users without affecting the rest of the organization, the administrator must configure both the Session Settings and Password Policies sections directly on the relevant profile.
In Salesforce, organization-wide Session Settings and Password Policies serve as defaults for the entire organization. However, administrators can override these defaults for specific user groups by editing the Session Settings and Password Policies directly on individual Profiles.

Step-by-Step Solution

1
Navigate to Setup and open the target Profile.
Locate the Call Center Representative profile configuration page.
Profile-level security settings allow specific user groups to have custom security policies that supersede organization-wide defaults.
2
Edit the Profile Session Settings.
Set the session timeout duration specifically to 30 minutes for this profile.
Session timeout overrides are maintained within the Profile Session Settings section.
3
Edit the Profile Password Policies.
Set the password expiration timeline specifically to 60 days for this profile.
Password expiration policies configured on a profile override the default organization password policy.

Key Concept

Profile-Level Security Overrides for Session Settings and Password Policies
Rate this question