Soru

Zorluk: Çok zorPermission Sets and Permission Set Groups

A system administrator at a healthcare enterprise needs to configure security access for a team of temporary clinical research contractors. The contractors require the standard object and field access bundled inside an existing Permission Set Group named 'Clinical_Operations_PSG', which includes Read, Create, Edit, and Delete access on the custom object 'Patient_Trial__c' as well as the 'Modify All Data' system permission.

Management has outlined two specific compliance constraints:
1. Clinical research contractors must NOT be granted Delete access on 'Patient_Trial__c' or the 'Modify All Data' system permission.
2. Existing operational staff currently assigned to 'Clinical_Operations_PSG' must retain their full access permissions without any modifications.
3. The contractors' access must automatically expire 60 days after assignment.

Which two actions should the administrator take to fulfill these requirements? (Select 2 answers)

  1. Create a new Permission Set Group for the research team that bundles the base permission sets, and include a Muting Permission Set within this new group to suppress Delete access on 'Patient_Trial__c' and 'Modify All Data'.Cevap
  2. Specify an Expiration Date of 60 days when assigning the new Permission Set Group to the clinical research contractors.Cevap
  3. C
    Add a Muting Permission Set directly to the existing 'Clinical_Operations_PSG' to mute Delete access on 'Patient_Trial__c' and 'Modify All Data'.
  4. D
    Clone the standard user profile assigned to the clinical research contractors and disable Delete access on 'Patient_Trial__c' and 'Modify All Data' at the profile level.

Cevap

To meet the compliance requirements, the administrator must create a distinct Permission Set Group containing a Muting Permission Set to restrict Delete and Modify All Data permissions specifically for contractors, and configure an assignment Expiration Date set to 60 days.
Creating a new dedicated Permission Set Group allows administrators to reuse base permission sets while attaching a Muting Permission Set to selectively disable Delete access and 'Modify All Data' strictly for contractors. Combining this with the native Permission Set Group assignment expiration feature ensures that access automatically expires in 60 days without affecting existing staff access.

Adım Adım Çözüm

1
Evaluate the impact of Muting Permission Sets on existing Permission Set Groups.
Recognize that adding a Muting Permission Set directly to the existing group would alter permissions for current operational staff.
Muting Permission Sets impact every user assigned to the Permission Set Group in which they reside.
2
Design a isolated Permission Set Group architecture.
Create a new Permission Set Group for contractors, re-use the base permission sets, and attach a Muting Permission Set that revokes Delete on 'Patient_Trial__c' and 'Modify All Data'.
This selectively restricts permissions for contractors while protecting existing staff access.
3
Configure user assignment lifecycle automation.
Set a 60-day assignment expiration date when assigning the new Permission Set Group to contractor user accounts.
Salesforce native user assignment expiration automatically revokes access upon the expiration date.

Anahtar Kavram

Permission Set Groups with Muting Permission Sets and User Assignment Expiration
Bu soruyu puanla