問題文
An org provisions users with Just-in-Time provisioning during SAML single sign-on. The identity provider knows which department each employee belongs to. How should profiles and permission sets be applied?
選択肢
- Have administrators assign the profile and the permission sets by hand after the first login, and run a monthly report that lists users whose assignments do not match their department so that the differences can be corrected before the next audit cycle.
- Give every user the same profile.
- Pass the values needed to determine access in the assertion and let the provisioning handler set the profile and assign permission sets when it creates or updates the user.
- Store the permission set assignments in the identity provider and let it enforce them at each login, which keeps one list of who may do what and saves the administrators a second place to maintain.