Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Salesforce Platform Identity and Access Management Architect
2 students

Salesforce Platform Identity and Access Management Architect

Pass the Salesforce Platform Identity and Access Management Architect Exam on First Attempt - New Salesforce Release
Last updated 2/2026
English

What you'll learn

  • Explain Salesforce identity architecture, including SSO, OAuth 2.0, and multifactor authentication.
  • Plan authentication, authorization, and identity federation across Salesforce and external systems.
  • Configure and manage My Domain, Identity Provider, and Connected Apps.
  • Apply best practices to troubleshoot, optimize, and scale identity and access management in enterprise environments. Ask ChatGPT

Included in This Course

600 questions
  • Identity and Access Management Architect Exam Simulator #1 - Study Mode100 questions
  • Identity and Access Management Architect Exam Simulator #2 - Study Mode100 questions
  • Identity and Access Management Architect Exam Simulator #3 - Study Mode100 questions
  • Identity and Access Management Architect Exam Simulator #4 - Study Mode100 questions
  • Salesforce Platform Identity and Access Management Architect #5 - Exam Mode100 questions
  • Salesforce Platform Identity and Access Management Architect #6 - Exam Mode100 questions

Description

About This Course & the Salesforce Platform Identity and Access Management Architect Certification

The Salesforce Certified Platform Identity and Access Management Architect credential validates the ability to design secure, high-performance access management solutions on the Salesforce Customer 360 platform. It’s intended for professionals who assess identity requirements, create scalable architectures, and communicate technical solutions effectively to both business and technical stakeholders.

Who This Certification Is For

This certification is well-suited for:

  • Enterprise Architects

  • Technical Architects

  • Security Architects

  • Integration Architects

  • Identity Architects

  • Solution Architects

Typical candidates have:

  • 1+ years of experience designing and implementing Identity and Access Management solutions on the Salesforce Customer 360 platform.

  • 2+ years of experience with identity and/or security technologies.

Skills You’ll Demonstrate in the Exam

By the end of this course, you’ll be able to:

  • Design identity architectures spanning multiple platforms, including integration and authentication across systems.

  • Configure Salesforce for delegated authentication, SAML (IdP-initiated and SP-initiated), and social sign-on.

  • Explain OAuth, SAML, OpenID Connect, and authentication for Salesforce Communities.

  • Establish trust between Identity Providers and Service Providers.

  • Apply two-factor authentication strategies and use login flows effectively.

  • Select the right identity federation approach for a given project.

  • Manage user lifecycles with automated provisioning, just-in-time provisioning, and manual account creation.

  • Troubleshoot and resolve common SSO issues.

You will not be tested on non-Salesforce IdP technologies, certificate procurement, or in-depth networking/domain management.

Exam Details

  • Format: 60 multiple-choice/multiple-select questions + up to 5 non-scored questions

  • Time Limit: 120 minutes

  • Passing Score: 67%

  • Version: Aligned with Salesforce Summer ’23 release

  • Cost: US$400 (retake: US$200) + applicable taxes

  • Delivery: Onsite or online proctored exam

  • Prerequisite: None

Exam Outline

The Salesforce Platform Identity and Access Management Architect Exam measures a candidate’s knowledge and skills related to the following objectives.


Identity Management Concepts: 17%

  • Describe common authentication patterns and understand the differences between each one.

  • Describe the building blocks that are part of an identity solution (authentication, authorization, and accountability) and how you enable those building blocks using Salesforce features.

  • Describe how trust is established between two systems.

  • Given a scenario, recommend the appropriate method for provisioning users in Salesforce.

  • Given a scenario, troubleshoot common points of failure that may be encountered in a single sign-on (SSO) solution (SAML, OAuth, etc.).

Accepting Third-Party Identity in Salesforce: 21%

  • Given a use case, describe when Salesforce is used as a Service Provider (SP).

  • Given a scenario, recommend the most appropriate way to provision users from identity stores in business-to-employer (B2E) and business-to-consumer (B2C) scenarios.

  • Given a scenario, recommend the appropriate authentication mechanism when Salesforce needs to accept third-party Identity (Enterprise Directory, Social, Community, etc.).

  • Given a scenario, identify the ways to provision users in Salesforce to enable SSO and apply access rights.

  • Given a scenario, identify the auditing and monitoring approaches available on the platform, and describe the tools available to diagnose Identity Provider (IdP) issues.

Salesforce as an Identity Provider: 17%

  • Given a scenario, identify the most appropriate OAuth flow (Web-based, JWT, User agent, Device auth flow).

  • Given a scenario, recommend appropriate Scope and Configuration of the Connected App for Authorization.

  • Describe the various implementation concepts of OAuth (scopes, secrets, tokens, refresh tokens, token expiration, token revocation, etc.).

  • Given a scenario, recommend the Salesforce technologies that should be used to provide identity to the third-party system (Canvas, Connected Apps, App Launcher, etc.).

Access Management Best Practices: 15%

  • Given a set of requirements, determine the most appropriate methods of multi-factor authentication (MFA) to use, and the right type of session they should yield.

  • Given a scenario, determine how to best assign roles, profiles, and permission sets to a user during the SSO process, how to keep these assignments up to date.

  • Given a scenario, describe which tools you can apply to audit and verify the activity/user during and after login.

  • Given a scenario, identify the configuration settings for a Connected App.

Salesforce Identity: 12%

  • Given a set of requirements, identify the role Identity Connect plays in a Salesforce Identity implementation.

  • Given a scenario, identify if Salesforce Customer 360 Identity fits into a fully-developed Customer 360 solution.

  • Give a set of requirements, recommend the most appropriate Salesforce license type(s).

Community (Partner and Customer): 18%

  • Describe the capabilities for customizing the user experience for Experience Cloud (Branding options, authentication options, identity verification self-registration, communications, password reset, etc.).

  • Given a set of requirements, determine the best way to support external IdPs in communities and leverage the right user/contact model to support community user experience.

  • Given a requirement, understand the advantages and limitations of External Identity solutions and associated licenses.

  • Given a scenario, determine when to use embedded login.

Who this course is for:

  • Salesforce Administrators & Security Professionals – Those managing user authentication, access control, and security policies. Solution & Technical Architects – Professionals designing secure identity solutions, authentication flows, and role-based access models. Salesforce Developers & Integration Specialists – Individuals implementing OAuth, SAML, OpenID Connect, and Single Sign-On (SSO) solutions. Identity & Access Management (IAM) Specialists – Those responsible for identity federation, external identity management, and compliance. Certification Candidates – Anyone preparing for the Salesforce Certified Identity and Access Management Architect exam and looking for structured learning and practice.