Delegated Administration allows additional Users with the Salesforce Platform license type to help the champion administer your Improveit 360 org.
A Delegated Administrator has limited permissions. They can assign Profiles, Permission Sets, Roles, and Permission Set Groups that have been assigned to their Delegated Admin Group.
Users who are going to be Delegated Administrators require the following System Permissions:
- Customize Application
- View Setup and Configuration
Creating a Delegated Administration Group
Setup > Security > Delegated Administration > New
Note: If you'd like your Delegated Administrators in this Group to be able to Login as another User, be sure to check Enable Group for Login Access. Use this setting with caution, as it allows them to impersonate another user. This should only be used for testing and troubleshooting access issues.
Delegated Administrators
Click "Add" to add Users who will be Delegated Administrators in your org. Use the lookup to search for Users.
User Administration
Add any Roles that this group should be able to administer and create new Users under. They will be able to administer the Role and its Subordinates.
Note: If your organization is not already using Roles, you'll need to create at least one Role and add all of your Users to it in order to utilize Delegated Administration.
Assignable Profiles
Add any Profiles that this group should be able to assign to Users it administers.
Assignable Permission Sets
Add any Permission Sets that this group should be able to assign to Users it administers.
Assignable Permission Set Groups
Add any Permission Set Groups that this group should be able to assign to Users it administers.
Assignable Public Groups
Add any Public Groups that this group should be able to assign to Users it administers.
Custom Object Administration
Add any Custom Objects that this group should be able to administer.
Note: Delegated Administrators can customize almost every aspect of specified custom objects. They are able to manage custom fields, page layouts, validation rules, tabs, and field sets. They cannot modify object relationships (lookup or master-details) or change the org-wide sharing settings. They cannot customize standard objects like the Account or Contact.
Example Delegated Admin Group:
Permissions are explicit. If the permission is not granted, the Delegated Administrator will not have access.
Grant Login Access does not allow you to login as another User while logged in as a Delegated Administrator. If you are the i360 Admin, you must login as the User. If you've used the Login access to login as the Delegated Admin, there will not be the ability to Login as another User.
Additional Resources:
Comments
0 comments
Please sign in to leave a comment.