Soru

Zorluk: ZorPermission Sets and Permission Set Groups

Universal Containers uses a single baseline custom profile for all 150 members of its global account management team. To support a new European privacy compliance audit, two account managers assigned to European accounts require temporary 'Edit' and 'Delete' permissions on a custom object named Compliance Audit (Compliance\_Audit__c). Company security policy mandates adhering to the principle of least privilege while minimizing ongoing administrative overhead and avoiding profile proliferation. How should the Salesforce administrator grant the required access to the two account managers?

  1. A
    Clone the existing custom profile to create a European Compliance Profile with 'Edit' and 'Delete' permissions on Compliance Audit, then assign this new profile to the two account managers.
  2. Create a standalone Permission Set granting 'Edit' and 'Delete' access on the Compliance Audit object, and assign it directly to the two account managers.Cevap
  3. C
    Modify the global baseline custom profile to grant 'Edit' and 'Delete' permissions on the Compliance Audit object, and use Organization-Wide Defaults to restrict access for the remaining 148 managers.
  4. D
    Create a new Role in the Role Hierarchy above the existing account management role, set object permissions on the Role, and assign the two managers to this new Role.

Cevap

The administrator should create a standalone Permission Set that grants 'Edit' and 'Delete' access on the custom object and assign it to the two specific account managers.
Creating a targeted Permission Set is the Salesforce best practice for granting additive permissions to a subset of users who share a baseline profile. This maintains least privilege, prevents profile proliferation, and allows simple assignment and removal of permissions.

Adım Adım Çözüm

1
Analyze access requirement scope
Identify that only 2 out of 150 users sharing a baseline profile require temporary additive object-level permissions.
Additive access needed for a subset of users should not alter the baseline profile shared by the entire team.
2
Evaluate administrative and security best practices
Determine that creating a Permission Set provides targeted additive CRUD access without profile duplication.
Permission Sets allow clean assignment and revocation of permissions while keeping user profiles streamlined.
3
Assign the Permission Set
Assign the created Permission Set specifically to the two European account managers.
This satisfies least privilege and prevents profile proliferation.

Anahtar Kavram

Permission Sets vs. Profiles for Additive Access
Tahmini Süre:2m 0s
Bu soruyu puanla