A company administrator needs to provision temporary access for a Customer Support Representative who is joining an internal audit task force for three months. The user must retain their current access to customer cases while gaining Read-only access to custom financial audit records. Which two actions should the administrator take to meet these requirements while adhering to the principle of least privilege?
- Assign a permission set to the user that grants Read access to the custom financial audit objects.Cevap
- Maintain the user's current Support Representative profile assignment.Cevap
- CChange the user's profile to Compliance Auditor and assign a permission set for support case access.
- DDeactivate the current user record and create a new user account assigned to the Compliance Auditor profile.
Cevap
The administrator should assign a permission set granting Read access to the custom financial audit objects and maintain the user's current Support Representative profile assignment.
In Salesforce, profiles define the core baseline permissions, while permission sets are used to grant additional permissions on an ad-hoc or temporary basis. Retaining the user's primary Support Representative profile maintains necessary ongoing case access, while applying a permission set grants the supplemental Read-only access to audit records in compliance with least privilege principles.
Adım Adım Çözüm
Anahtar Kavram
User Provisioning and Additive Access via Permission Sets
Tahmini Süre:1m 30s