Salesforce Certified Identity and Access Management Designer Exam
Certified Identity and Access Management Designer (Page 12 )

Updated On: 9-Feb-2026

A group of users try to access one of Universal Containers' Connected Apps and receive the following error message: " Failed: Not approved for access." What is the most likely cause of this issue?

  1. The Connected App settings "All users may self-authorize" is enabled.
  2. The Salesforce Administrators have revoked the OAuth authorization.
  3. The Users do not have the correct permission set assigned to them.
  4. The Userof High Assurance sessions are required for the Connected App.

Answer(s): C



Which tool should be used to track login data, such as the average number of logins, who logged in more than the averagenumber of times and who logged in during non-business hours?

  1. Login Inspector
  2. Login History
  3. Login Report
  4. Login Forensics

Answer(s): D



Which three are features of federated Single sign-on solutions? Choose 3 Answers

  1. It establishes trust between Identity Store and Service Provider.
  2. It federates credentials control to authorized applications.
  3. It solves all identity and access management problems.
  4. It improves affiliated applications adoption rates.
  5. It enables quick and easy provisioning and deactivating of users.

Answer(s): A,D,E



Universal Containers (UC) is both a Salesforce and Google Apps customer. The UC IT team would like to manage the users for both systems in a single place to reduce administrative burden.
Which two optimal ways can the ITteam provision users and allow Single Sign-on between Salesforce and Google Apps ? Choose 2 answers

  1. Build a custom app running on Heroku as the Identity Provider that can sync user information between Salesforce and Google Apps.
  2. Use a third-party product as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.
  3. Use Identity Connect as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.
  4. Use Salesforce as theIdentity Provider and Google Apps as a Service Provider and configure User Provisioning for Connected Apps.

Answer(s): B,D



Universal Containers (UC) is building a custom Innovation platform on their Salesforce instance. The Innovation platform will be written completely in Apex and Visualforce and will use custom objects to store the Data. UC would like all users to be able to access the system without having to log in with Salesforce credentials. UC will utilize a third-party idp using SAML SSO.
What is the optimal Salesforce licence type for all of the UC employees?

  1. Identity Licence.
  2. Salesforce Licence.
  3. External Identity Licence.
  4. Salesforce Platform Licence.

Answer(s): D






Post your Comments and Discuss Salesforce Certified Identity and Access Management Designer exam prep with other Community members:

Join the Certified Identity and Access Management Designer Discussion