Soru

Zorluk: ZorPermission Sets and Permission Set Groups

A renewable energy corporation uses a single baseline profile to grant standard read-only access to all 40 regional operations managers. To streamline an upcoming quarterly grid maintenance program, 8 of these managers require temporary edit permissions on a custom Inverter Asset object and the ability to run data exports. Following the maintenance program, these additional privileges must cease. Which solution should the system administrator implement to meet these access requirements while adhering to Salesforce security best practices?

  1. A
    Create custom profiles for the 8 regional managers with edit permissions on the Inverter Asset object and export access, then reassign their profile back to standard read-only after the maintenance period.
  2. Create a permission set granting edit access to the Inverter Asset object and export permissions, assign it to the 8 managers, and set an expiration date on the permission set assignment.Cevap
  3. C
    Modify the baseline profile to enable Organization-Wide Defaults to Public Read/Write for the Inverter Asset object during the maintenance window.
  4. D
    Clone the standard user profile for the 8 managers, enable field-level edit access, and update the role hierarchy to automatically revoke access when the program ends.

Cevap

Create a permission set granting edit access to the custom object and export permissions, assign it to the specific managers, and configure an expiration date on the permission set assignment.
The option advocating a Permission Set with an expiration date is correct because permission sets grant additive permissions without modifying baseline profiles. Leveraging assignment expiration dates ensures temporary privileges are automatically revoked upon completion of the maintenance period.

Adım Adım Çözüm

1
Analyze the access requirement type
Identify that the 8 managers require additive object-level permissions and system privileges on top of their baseline profile, limited to a specific time frame.
Profiles should define minimum baseline access shared by a job function, while Permission Sets layer on extra permissions for specific subsets of users.
2
Evaluate permission assignment tools for temporary access
Determine that assigning a Permission Set with an Expiration Date satisfies both the additive requirement and the automated time-bound cleanup requirement.
Permission Set assignment expiration dates automatically revoke user access when the specified duration concludes, eliminating manual admin oversight.
3
Evaluate and reject profile-based alternatives
Reject profile cloning, profile reassignment, and OWD alterations.
Profile modifications introduce administrative sprawl and risk altering baseline access for unaffected users.

Anahtar Kavram

Additive permissions and access lifecycle management using Permission Sets and Expiration Dates
Tahmini Süre:2m 0s
Bu soruyu puanla