Skip to main content

#Identity and Access Management0 discutindo

A Salesforce Certified Identity and Access Management Specialist assesses the architecture environment and requirements; and designs sound and scalable technical solutions on the Force.com that meet the Single Sign on (SSO) requirements.

https://sforcemaximizer.com/mastering-salesforce-identity-and-access-management-architect-exam-a-practical-approach-to-exam-preparation-with-my-course/

If you are an admin, developer or architect looking to pass the Salesforce Identity Access Management exam, my blog will provide you the details of a course which I recently authored in Salesforce Ben and help you pass the exam. This is a tough exam due to lack of topic areas where there is not many opportunities to work and get experience on and hope my course helps folks on there journey to CTA!!

@SecurityForce @* Salesforce Administrators * @Admin Tricks@Manufacturing User Group@Higher Ed User Group, Northeast, US@Architect Group, Austin, TX US@Architect Group, Boston, US@Architect Group, Orlando, US@Architect Group, Columbus, OH, US@Architect Group, Los Angeles, US@Architect Group, London, UK@Architect Group, Chennai, IN

 

#Identity and Access Management  #Security

0/9000

Hello, I am preparing for the Identity and Access Management Architect credential.

 

Some time ago, before there was Experience Cloud, I would use either Customer Community and Customer Community Plus licenses for customers logging in to Customer Communities, or Partner Community licenses for partners logging in to Partner Communities.

 

Now we have 2 identity licenses - Identity Only and External Identity:

Salesforce Identity Licenses

 

Identity Only - A license for Salesforce employees (internal users) that want to use Salesforce for logging in to a service outside Salesforce. In this case that would be a user using Salesforce as Identity Provider, but using an external Service Provider app. Yes or no?

 

External Identity - A license for Salesforce consumers of your business, such as customers, prospective customers, patients, partners, and dealers (external users). I don't understand the purpose of this license. As I wrote above, customers and partners have had their own license for some time. Can anyone explain the reasoning behind this?

 

#Identity and Access Management #Technical Architect #Solution Architects #Experience Cloud

10 respostas
0/9000

User provisioning question - what options do we have to sync user attribute data and provision users in Salesforce from an on-premise system that does not have any prebuilt connectors (like OKTA, AD etc) with no SSO (so no SAML JIT). Is it pretty much limited to using SOAP or REST callouts?

#User Provisioning #Identity and Access Management

1 resposta
  1. Manoj Nambirajan (Dell Technologies) Forum Ambassador
    11 de jul. de 2022, 12:15

    yes.. dont see any other option. Could potentially be a webservice call out (soap or rest api) which compares user existence in SFDC while comparing with on-prem system and create user accordingly.

0/9000

I am looking at the documentation for IdP and SP initiated SAML and seem to come across conflicting information if the IdP-initiated SAML supports deep linking. From what I understand, myDomain is required for deep linking in both cases (though generally optional for IdP-initiated SAML) and the IdP must support the RelayState parameter, but then I see other posts saying that only SP-initiated SAML can support deep linking. So which one is correct?

#SAML Single Sign On #Deep Links #IdP Vs SP #Identity and Access Management

1 resposta
0/9000

Is Salesforce's "OAuth 2.0 User-Agent Flow the same as OAuth Implicit Flow?  Salesforce documentation references OAuth 2.0 User-Agent Flow, but I can't find a reference to this name in any non-Salesforce documentation.  From reading the description of the flow, it *almost* matches what other OAuth-related resources call Implicit Flow or Implicit Grant.  BUT, the Implicit Flow doesn't return a refresh token, while documentation for User-Agent Flow say that a refresh token is returned.  Furthermore, non-Salesforce documents discourage the use of Implicit Flow and instead now recommend Authorization Code with PKCE as an alternative.  So what is this User-Agent flow and how does it map to the flows defined in the OAuth standard?

@Ladies Be Architects #Identity and Access Management #OAuth Flow #Security 

2 comentários
  1. 17 de fev. de 2020, 13:41

    Hi guys,

    Following up on this:

    We have a requirement to use PKCE for OAuth flows.

    Does Salesforce now support PKCE flows ? and if so where can we get access to docuemntation that illustrates how this can be configured.

    Kind Regards

0/9000

That SSO session was amazing - thanks so much to @Charly Deloitte Prinsloo  for taking us through it. Join us for an in-depth tour around SSO with SAML! We talk about federated authentication, IdP vs SP-initiated flows, SAML parameters and My Domain.

SSO & SAML Study Group - Oct 2018

1 comentário
0/9000

@Charly Deloitte Prinsloo  How to access the slide deck of your presentation , Single Sign-On & SAML (Oct. 2018)? Many thanks!

0/9000

Thank you to everybody who took part in @Natalya Murphy's Identity and Access Management study group:

 

John M. Daniel, Madhavi R., Harish Dintakurthi, Winnie Vu, Terry Miller, David Bergerson, Jeff Hunsaker, Svatka Simpson, Luz Paulina Chavez, Brenda Glasser, Amit Jain, Pavithra Vishwanath, Clara Pérez, Satish Penmethsa, Edith Valencia Martínez, Jaseem Pookandy, Igor Androsov and Joseph Thomas

 

And finally, to the lady herself, Natalya Murphy, who has given about 50 hours of her time this year to help others study towards this and the Integration Architecture exam this year. This is amazing content that will help people all over the world get certified in some of the most advanced areas of working with the hashtag#salesforce platform.

 

Thank you from the bottom of our hearts. We are really pleased to share the whole study group with you which can be found on YouTube. Don't forget to subscribe for more content :0)

Identity and Access Management Study Group

2 comentários
  1. 31 de dez. de 2018, 23:26
    @Natalya Murphy is fantastic! I appreciate all her efforts and the efforts of my fellow study partners. Great work all!
0/9000

Three more recordings available this week around #Identity and Access Management - thank you to @Natalya Murphy and ALL of her special guests for providing such great content to support others with this challenging exam

 

@Architect Trailblazers 

PLAYLIST: Identity & Access Management Study Group

1 comentário
  1. 3 de dez. de 2018, 12:45
    Thanks! This is my next exam and I will have System Architect! CTA in 2019 is my goal!
0/9000

I need some help understanding the answer to a sample question in the Identity and Access Management Designer study guide.

 

Sample question:

Universal Containers (UC) has chosen to implement a hub-and-spoke Salesforce org strategy where a subset of users in the hub org should be able to access resources in any of the spoke orgs. The IT team at UC has decided they would like to manage users in the hub org and automatically create those  users in the spoke orgs, as needed, to reduce administrative burden. They will configure the hub org as an Identity Provider and use SAML to authenticate users in the spoke orgs. What is the recommended solution for automatically creating users in the spoke orgs?

 

The 2 best options are:

A. Use an IdP-initiated SAML flow and Custom SAML JIT Provisioning to create users in the spoke orgs.

B. Use an IdP-initiated SAML flow and Salesforce SAML JIT Provisioning to create users in the spoke orgs. 

 

The correct answer is to use the Custom option (A), but I don't see anything in the documents I've found on WHY the standard option wouldn't work.  Is it just the fact that the actual options on the SSO config screen say "Standard" and "Custom SAML JIT with Apex handler", or is there some other critical piece of information I'm overlooking in the question that would point to the need for a custom solution?

 

@Ladies Be Architects #Identity and Access Management 

4 comentários
  1. 30 de nov. de 2018, 12:35

    If the IdP connecting to the org for which we sign up SSO for is

    definitely providing all those required values including ProfileId or

    ProfileName - I believe some advanced identity management platform

    (Ping? Okta?) can do that, thus in that scenario you will use Standard

    JIT.

0/9000