Soru

Zorluk: Çok zorUser Management and Provisioning

A Salesforce Administrator needs to manually provision a new sales executive user account in a complex enterprise Salesforce org. The user requires access to standard CRM features, specialized custom object permissions, and specific data access defined by organizational hierarchy. What is the correct sequence of administrative steps to configure and provision this user account following Salesforce best practices?

  1. 1Select the appropriate User License (e.g., Salesforce) and assign a minimal base Profile to establish baseline administrative and system permissions.
  2. 2Assign the user to their designated Role within the Role Hierarchy to establish record-level access and sharing visibility.
  3. 3Assign Permission Sets or Permission Set Groups to grant supplemental custom object, field-level, and functional permissions.
  4. 4Save the user record with 'Generate new password and notify user immediately' enabled to complete activation and send the onboarding notification email.

Cevap

The correct sequence for provisioning a new enterprise user is: 1) Select the User License and assign a minimal base Profile, 2) Assign the designated Role within the Role Hierarchy, 3) Assign Permission Sets or Permission Set Groups for specialized access, and 4) Save the user record to trigger activation and send the welcome notification.
The correct sequence follows Salesforce provisioning best practices: first establish base identity and license limits via the User License and base Profile, set up data access hierarchy via the Role, extend specific functional access using Permission Sets, and finally save the record to initiate activation and dispatch access credentials.

Adım Adım Çözüm

1
Define core user credentials and baseline license settings.
User License is bound to the record, which governs available profiles.
User License selection is mandatory upon user record creation and cannot be changed to an incompatible profile type later.
2
Assign the Role location in the organizational hierarchy.
Record-level access rules and hierarchy sharing rollups are established.
Roles control record visibility, which should be configured alongside base identity settings.
3
Grant granular object and field permissions via Permission Sets.
Elevated permissions are granted without broadening base profile permissions.
Modern Salesforce architecture emphasizes least-privilege profiles paired with permission set assignments.
4
Save and dispatch welcome credentials.
The user account transitions to active state and the login URL email is sent.
Account activation and user notification complete the administrative provisioning workflow.

Anahtar Kavram

User Provisioning & Least Privilege Permissioning Workflow
Bu soruyu puanla