Question

Difficulty: EasyDelegated Administration

Match each Salesforce Delegated Administration feature with its corresponding operational scope and administrative capability.

  • Delegated User ManagementCreate and edit users, unlock accounts, and reset passwords for users in specified roles and subordinate roles.
  • Delegated Profile AssignmentAssign users to a restricted list of profiles specified in the delegated administration group setup.
  • Delegated Custom Object AdministrationCreate and manage custom fields, page layouts, and record types for designated custom objects.
  • Delegated Administrator Login AccessLog in as users who belong to managed roles and have enabled login permission for administrators.

Answer

Delegated User Management matches creating/editing users and resetting passwords within specified roles. Delegated Profile Assignment matches assigning only designated profiles added to the delegated group. Delegated Custom Object Administration matches managing fields, layouts, and record types on specified custom objects. Delegated Administrator Login Access matches logging in as users in managed roles who granted access.
Each feature of Delegated Administration maps directly to its predefined security boundary in Salesforce Setup. Delegated user management controls users in specific role hierarchies; profile assignment is bounded by assigned profile lists; custom object delegation allows schema changes for designated custom objects; and login privileges require user consent within delegated role structures.

Step-by-Step Solution

1
Analyze user management scope for delegated administration.
User maintenance capabilities are scoped to users in defined roles and subordinate roles in the role hierarchy.
Salesforce scopes user administration delegation using specified role trees to enforce least privilege.
2
Determine profile assignment limits for delegated administrators.
Profile permissions are strictly restricted to profiles explicitly assigned to the delegated group.
This prevents delegated admins from elevating user privileges beyond approved organizational roles.
3
Examine object administration privileges.
Custom object administration permits field, page layout, and record type management for specified custom objects.
Delegated object administration is strictly limited to specified custom objects and cannot modify standard objects.
4
Evaluate login access requirements.
Logging in as another user requires the target user to reside in a delegated role and explicitly grant login access.
Login permissions require both role delegation boundaries and user authorization.

Key Concept

Delegated Administration Boundaries and Capabilities
Estimated Time:1m 0s
Rate this question