Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Salesforce
Exam Format
Registration
Validity
IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER Exam Topics and Domains
IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER is organized into 6 weighted domains. Expect to work with Connected Apps, OAuth 2.0, SAML, App Launcher, and more.
Identity Management Concepts
Identity Provider and Service Provider Roles
- Describe the role(s) an identity provider and service provider play in an access control solution
- Describe common methods how trust connections are established between two systems and the methodologies used to describe trust between an identity provider and service provider
Authentication, Authorization, and Accounting
Given a scenario, articulate whether it is describing an authentication, authorization, or accounting scenario and what Salesforce feature should be used to accomplish the task
User Provisioning Methods
Given a scenario, recommend the appropriate method for provisioning users in Salesforce and other third party services (SOAP/REST API, SAML JIT, Identity Connect, User Provisioning for Connected Apps, etc.)
Federated SSO Security
Describe the risks to enterprise security that federated single sign-on solutions aim to address
SSO Troubleshooting
Given a scenario, troubleshoot common points of failure that may be encountered in a single sign-on solution (SAML, OAuth, etc.)
Accepting 3rd Party Identity in Salesforce
Identity Management Solution Components
Describe the components of an identity management solution where Salesforce is accepting identity from a 3rd party
3rd Party Authentication Mechanisms
Given a scenario, recommend the appropriate authentication mechanism when Salesforce needs to accept 3rd Party Identity (Enterprise Directory, Social, Community, etc.)
SAML Initiation Methods
Given a scenario, recommend the appropriate method of SAML initiation to fulfill the requirements (SP-init, IdP-init.)
Delegated Authentication
- Describe the components of a Delegated Authentication solution
- Describe the risks of implementing delegated authentication
Salesforce as an Identity Provider
OAuth Flow Selection
Given a scenario, determine the most appropriate flow type to recommend when implementing an OAuth solution where Salesforce is providing identity to a 3rd party (E.g. User Agent, Web Server, JWT, etc.)
OAuth Implementation Concepts
Describe the various implementation concepts of OAuth (E.g. scopes, secrets, tokens, refresh tokens, token expiration, token revocation, etc.)
Connected Apps Role
Describe the role(s) Connected Apps play when Salesforce needs to provide identity to a third party system
Identity Provisioning Technologies
Given a scenario, recommend the Salesforce technologies that should be used to provide identity to the 3rd party system. (Canvas, Connected Apps, App Launcher, etc.)
Access Management Best Practices
Two-Factor Authentication (2FA)
- Describe the risks that Two-Factor Authentication mechanisms aim to mitigate
- Given a scenario, determine the most appropriate Two-Factor Authentication mechanism for an identity solution
Session Security
Given a scenario, identify the risks and mitigation strategies that session security and Two-Factor Authentication enable (E.g. High Assurance Sessions, 2FA, etc.)
Salesforce Identity
Salesforce License Types
Given a scenario, recommend the most appropriate Salesforce license type(s) to support the identity requirements
Identity Connect
Describe the role(s) Identity Connect plays in an Identity Management solution
Login Flows
Explain the use of Login Flows
App Launcher
Describe when to and how to implement App Launcher
Community (Partner and Customer)
Community Registration Customization
Describe the capabilities for customizing the registration experience for external communities (E.g. Branding options, self-registration, communications, etc.)
How do I earn this certification?
Passing IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER earns the Salesforce Certified Platform Identity and Access Management Architect certification. It sits in the Architect Track - Designer Level track.
- Technical Architect Review Board Highest level Salesforce certification; requires multiple architect certifications
- System Architect - System Architect Complementary architect certification focusing on system design
- Application Architect - Application Architect Complementary architect certification focusing on application design
- Integration Architect - Salesforce Certified Integration Architect Related skills in integration and authentication patterns
- Data Architect - Salesforce Certified Data ArchitectComplementary skills in data security and governance
- Sharing and Visibility Designer - Salesforce Certified Sharing and Visibility Designer Complementary security and access control knowledge
- B2C Solution Architect - Salesforce Certified B2C Solution ArchitectCustomer identity and Experience Cloud expertise
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
Use the official PlanetCert Practice Test alongside the study plan below to prepare efficiently for IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER.
What's changed on this exam?
- ACTIVE
- Last content update: Winter '19
- Passkey/WebAuthn Support Current Likely to be included in future exam updates as passwordless authentication gains adoption • Release date: 2024-10-01
- OAuth 2.1 Enhancements Current Security best practices and PKCE requirements may appear in exam scenarios • Release date: 2024-06-01
- Identity Connect 4.0 4.0 Enhanced Active Directory integration features covered in exam • Release date: 2023-08-01
- Experience Cloud Authentication Current Community authentication remains significant portion of exam (17% domain) • Release date: 2024-03-01