Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) Exam - Topic 3 Question 79 Discussion
Northern Trail Outfitters (NTO) has an off-boarding process where a terminated employee is first disabled in the Lightweight Directory Act Protocol (LDAP) directory, then requests are sent to the various application support teams to finish user deactivations. A terminated employee recently was able to login to NTO's Salesforce instance 24 hours after termination, even though the user was disabled in the corporate LDAP directory.What should an identity architect recommend to prevent this from happening in the future?
B) Configure an authentication provider to delegate authentication to the LDAP directory.
A) Create a Just-in-Time provisioning registration handler to ensure users are deactivated in Salesforce as they are disabled in LDAP.
C) use a login flow to make a callout to the LDAP directory before authenticating the user to Salesforce.
D) Setup an identity provider (IdP) to authenticate users using LDAP, set up single sign-on to Salesforce and disable Login Form authentication.
Sheron
13 days agoEden
18 days agoTequila
23 days agoGraciela
29 days agoMarilynn
1 month agoRodolfo
1 month agoColette
1 month agoAndree
2 months agoAsuncion
2 months agoDevora
2 months agoAntonio
2 months agoVicky
2 months ago