Exam Name: Salesforce Certified Platform Identity and Access Management Architect

Exam Code: Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)

Related Certification(s): Salesforce Architect Certification

Certification Provider: Salesforce

Actual Exam Duration: 120 Minutes

Number of Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) Practice Questions: 248 (updated: )

Expected Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) Exam Topics:
Topic 1: Identity Management Concepts
This topic covers common authentication patterns, building blocks of identity solutions (authentication, authorization, accountability), and establishing trust between systems. It also includes methods for provisioning users in Salesforce and troubleshooting common points of failure in SSO solutions.
Topic 2: Accepting Third-Party Identity in Salesforce
It discusses cases where Salesforce acts as a Service Provider (SP), methods for provisioning users from identity stores (B2E, B2C), appropriate authentication mechanisms for accepting third-party identities, and ways to provision users to enable SSO while applying access rights. Moreover, the topic also addresses auditing, monitoring approaches, and tools to diagnose IdP issues.
Topic 3: Salesforce as an Identity Provider
In this topic, you’ll find information on OAuth flows, configuring Connected Apps for authorization, and implementation concepts of OAuth. It also recommends Salesforce technologies to provide identity to third-party systems.
Topic 4: Access Management Best Practices
This topic covers methods of multi-factor authentication (MFA), assigning roles, profiles, and permission sets during SSO, auditing and verifying activity post-login, and configuring settings for a Connected App.
Topic 5: Salesforce Identity
This topic explains the role of Identity Connect in Salesforce Identity implementations, the fit of Salesforce Customer 360 Identity in a comprehensive Customer 360 solution, and recommendations for Salesforce license types based on specific requirements.
Topic 6: Community (Partner and Customer)
Here, you’ll find details on customizing user experiences in Experience Cloud, supporting external IdPs in communities, understanding External Identity solutions and associated licenses, and when to use embedded login based on different scenarios.
Free Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) Exam Actual Questions
Note: Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) Premium Questions were last updated on

Q1. A consumer products company uses Salesforce to maintain consumer information, including orders.

The company implemented a portal solution using Salesforce Experience Cloud for its consumers where the consumers can log in using their credentials.

The company is considering allowing users to login with their Facebook or LinkedIn credentials.

Once enabled, what role will Salesforce play?

Q2. Universal Containers (UC) uses a home-grown Employee portal for their employees to collaborate.

UC decides to use Salesforce Ideas to allow employees to post Ideas from the Employee portal.

When users click on some of the links in the Employee portal, the users should be redirected to Salesforce, authenticated, and presented with the relevant pages.

What OAuth flow is best suited for this scenario?

Q3. Users logging into Salesforce are frequently prompted to verify their identity.

The identity architect is required to provide recommendations so that the frequency of prompt verification can be reduced.

What should the identity architect recommend to meet the requirement?

Q4. Universal Containers (UC) would like to enable SAML-based SSO for a Salesforce partner community.

UC has an existing LDAP identity store and a third-party portal.

They would like to use the existing portal as the primary site these users access, but also want to allow seamless access to the partner community.

What SSO flow should an architect recommend?

Q5. Northern Trail Outfitters (NTO) wants its customers to use phone numbers to log in to their new digital portal, which was designed and built using Salesforce Experience Cloud.

In order to access the portal, the user will need to do the following:

1. Enter a phone number and/or email address.

2. Enter a verification code that is to be sent via email or text.

What is the recommended approach to fulfill this requirement?