Salesforce IAM Architect Study Guide

Salesforce-Certified-Platform-Identity-and-Access-Management-Architect

Salesforce Certified Platform Identity and Access Management Architect Preparation Details

The Salesforce Certified Platform Identity and Access Management Architect exam validates your ability to design secure identity solutions on the Customer 360 platform. This guide maps every official objective to verified Salesforce documentation covering SSO, OAuth, provisioning, and Experience Cloud community identity. You can also explore more Salesforce certification study guides on the Salesforce Certifications category to keep building your skills.

Salesforce Certified Platform Identity and Access Management Architect Materials

CourseraIdentity and Access Management (IAM)
UdemySalesforce Identity and Access Management Architect

Identity Management Concepts: 17%

Describe common authentication patterns and understand the differences between each one.

Single Sign-On

OAuth Authorization Flows

Salesforce as an Identity Provider

Configure Salesforce for Delegated Authentication

Authentication Provider SSO with Salesforce as the Relying Party

Describe the building blocks that are part of an identity solution (authentication, authorization, and accountability) and how you enable those building blocks using Salesforce features.

Identify Your Users and Manage Access

Multi-Factor Authentication for Salesforce Orgs

Permissions and Access Settings

Monitor Login History

Monitor Setup Changes with Setup Audit Trail

Describe how trust is established between two systems.

Enable Salesforce as a SAML Identity Provider

Configure SSO with Salesforce as a SAML Service Provider

Salesforce SSL/TLS Certificate Trust

Create an Identity Provider Chain

Given a scenario, recommend the appropriate method for provisioning users in Salesforce.

Just-in-Time Provisioning for SAML

Enable Just-in-Time Provisioning

Manage Salesforce User Identities with SCIM

Identity Connect

Configure User Provisioning for Connected Apps

Given a scenario, troubleshoot common points of failure that may be encountered in a single sign-on (SSO) solution (SAML, OAuth, etc.).

SAML Login Errors

OAuth 2.0 Authorization Errors

Troubleshoot Delegated Authentication Login Errors

Use the Identity Provider Event Log

Monitor Login History

Accepting Third-Party Identity in Salesforce: 21%

Given a use case, describe when Salesforce is used as a Service Provider (SP).

Salesforce as a Service Provider

Configure SSO with Salesforce as a SAML Service Provider

Salesforce as Service Provider and Identity Provider for SSO

Authentication Provider SSO with Salesforce as the Relying Party

Given a scenario, recommend the most appropriate way to provision users from identity stores in business-to-employer (B2E) and business-to-consumer (B2C) scenarios.

Just-in-Time Provisioning for SAML

Identity Connect

Salesforce Customer Identity

Manage Salesforce User Identities with SCIM

Configure User Provisioning for Connected Apps

Given a scenario, recommend the appropriate authentication mechanism when Salesforce needs to accept third-party Identity (Enterprise Directory, Social, Community, etc.).

Identity Connect

Authentication Provider SSO with Salesforce as the Relying Party

Salesforce Customer Identity

Configure Your Experience Cloud Site as an Identity Provider or OpenID Provider

Single Sign-On for Salesforce Customer Identity

Given a scenario, identify the ways to provision users in Salesforce to enable SSO and apply access rights.

Just-in-Time SAML Assertion Fields for Salesforce

Enable Just-in-Time Provisioning

Profiles

Permission Set Groups

Manage Salesforce User Identities with SCIM

Given a scenario, identify the auditing and monitoring approaches available on the platform, and describe the tools available to diagnose Identity Provider (IdP) issues.

Monitor Access to Your Salesforce Orgs and Experience Cloud Sites

Use the Identity Provider Event Log

Monitor Login History

Monitor Setup Changes with Setup Audit Trail

Monitor Apps with Reports

Salesforce as an Identity Provider: 17%

Given a scenario, identify the most appropriate OAuth flow (Web-based, JWT, User agent, Device auth flow).

OAuth Authorization Flows

OAuth 2.0 Web Server Flow for Web App Integration

OAuth 2.0 User-Agent Flow for Desktop or Mobile App Integration

OAuth 2.0 JWT Bearer Flow for Server-to-Server Integration

OAuth 2.0 Device Flow for IoT Integration

Given a scenario, recommend appropriate Scope and Configuration of the Connected App for Authorization.

Create a Connected App

Enable OAuth Settings for API Integration

OAuth Tokens and Scopes

Manage OAuth Access Policies for a Connected App

OAuth Custom Scopes

Describe the various implementation concepts of OAuth (scopes, secrets, tokens, refresh tokens, token expiration, token revocation, etc.).

OAuth Tokens and Scopes

Access Tokens

OAuth 2.0 Refresh Token Flow

Revoke OAuth Tokens

Authorize Apps with OAuth

Given a scenario, recommend the Salesforce technologies that should be used to provide identity to the third-party system (Canvas, Connected Apps, App Launcher, etc.).

Expose Your Connected App as a Canvas App

Create a Connected App

App Launcher

External Client Apps and Connected Apps

Salesforce as an Identity Provider

Access Management Best Practices: 15%

Given a set of requirements, determine the most appropriate methods of multi-factor authentication (MFA) to use, and the right type of session they should yield.

Multi-Factor Authentication for Salesforce Orgs

Verification Methods for Multi-Factor Authentication

Session Security

Modify Session Security Settings

Require High-Assurance Session Security for Sensitive Operations

Given a scenario, determine how to best assign roles, profiles, and permission sets to a user during the SSO process, how to keep these assignments up to date.

Just-in-Time SAML Assertion Fields for Salesforce

Profiles

Permission Set Groups

Permissions and Access Settings

Given a scenario, describe which tools you can apply to audit and verify the activity/user during and after login.

Monitor Login History

Monitor Setup Changes with Setup Audit Trail

Monitor Access to Your Salesforce Orgs and Experience Cloud Sites

Use the Identity Provider Event Log

Monitor Apps with Reports

Given a scenario, identify the configuration settings for a Connected App.

Create a Connected App

Manage OAuth Access Policies for a Connected App

Manage Session Policies for a Connected App

Manage Access to a Connected App

Configure User Provisioning for Connected Apps

Salesforce Identity: 12%

Given a set of requirements, identify the role Identity Connect plays in a Salesforce Identity implementation.

Identity Connect

Install Identity Connect

Who Is Salesforce Identity For?

Identify Your Users and Manage Access

Given a scenario, identify if Salesforce Customer 360 Identity fits into a fully-developed Customer 360 solution.

Salesforce Customer Identity

Who Is Salesforce Identity For?

External Identity License Details

Prepare Your Org for Salesforce Customer Identity

Give a set of requirements, recommend the most appropriate Salesforce license type(s).

Salesforce Identity Licenses

External Identity License Details

Licenses Overview

Learn More About Experience Cloud Licenses

Community (Partner and Customer): 18%

Describe the capabilities for customizing the user experience for Experience Cloud (Branding options, authentication options, identity verification self-registration, communications, password reset, etc.).

Brand Your Identity Pages with Dynamic URLs

Single Sign-On for Salesforce Customer Identity

Self-Registration

Customize Login, Logout, and Password Management Pages

Passwordless Login

Given a set of requirements, determine the best way to support external IdPs in communities and leverage the right user/contact model to support community user experience.

Configure Your Experience Cloud Site as an Identity Provider or OpenID Provider

Control Authorization with Custom Profiles and Roles

Control User Access to Your Experience Cloud Site

Salesforce Customer Identity

Single Sign-On for Salesforce Customer Identity

Given a requirement, understand the advantages and limitations of External Identity solutions and associated licenses.

External Identity License Details

Learn More About Experience Cloud Licenses

Manage Sites with Contactless Users

Salesforce Identity Licenses

Given a scenario, determine when to use embedded login.

Embedded Login

Embedded Login Considerations

Single Sign-On for Salesforce Customer Identity

Configure Your Experience Cloud Site as an Identity Provider or OpenID Provider

Wrapping Up Salesforce Certified Platform Identity and Access Management Architect

This study guide covered all six domains of the Salesforce Certified Platform Identity and Access Management Architect exam, from authentication patterns and OAuth flows to Experience Cloud community identity. With the documentation links above, you can systematically work through SSO, provisioning, and access management concepts before test day. You can also explore more Salesforce certification study guides on the Salesforce Certifications category to keep building your skills. Have a question or tip? Leave a comment below.

Receive Updates on Salesforce Certified Platform Identity and Access Management Architect Exam


Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.

Share the Salesforce Certified Platform Identity and Access Management Architect Study Guide in Your Network

You may also like

Leave a Reply

Your email address will not be published. Required fields are marked *