Soru

Zorluk: OrtaDelegated Administration

Vanguard Global Tech needs to grant regional helpdesk supervisors administrative permissions over user accounts strictly within the 'APAC Support' role hierarchy without providing full System Administrator access. The Salesforce administrator creates a Delegated Administration group for these supervisors.

Which two administrative capabilities can be granted to the helpdesk supervisors through this Delegated Administration group? (Select 2 options)

  1. Unlocking user accounts and resetting passwords for users within the specified role hierarchyCevap
  2. Assigning specified permission sets to users within the delegated user scopeCevap
  3. C
    Creating new custom profiles to grant additive object permissions to users in the delegated role
  4. D
    Deactivating user accounts that are currently assigned as default lead owners in system settings without freezing them first

Cevap

Delegated administrators can unlock accounts, reset passwords, and assign pre-approved permission sets to users within their assigned roles and subordinate roles.
Delegated Administration allows administrators to grant specific management rights over users in assigned roles. Valid delegated tasks include unlocking accounts, resetting passwords, editing specified user fields, assigning specified profiles, and assigning pre-approved permission sets.

Adım Adım Çözüm

1
Analyze the capabilities permitted within Salesforce Delegated Administration groups.
Delegated administration allows specific non-admin users to manage users in specified roles (unlocking, resetting passwords, editing fields) and assign specified permission sets.
Delegated administration provides targeted user management scope without exposing full system administrator rights.
2
Evaluate limitations of delegated administration regarding profiles and user status operations.
Delegated admins cannot edit or create profile definitions, nor can they bypass standard deactivation constraints for users tied to default system references.
Profile modification rights are restricted to prevent unauthorized privilege escalation, and deactivation constraints protect system automation integrity.

Anahtar Kavram

Delegated Administration Scope and Privileges
Bu soruyu puanla