
Study map for Salesforce Platform Identity and Access…. Confirm objectives on current Salesforce sources.
Salesforce Platform Identity and Access Management Architect
Catalog status checked July 19, 2026: Available.
Current credential snapshot
| Item | Current listing |
|---|---|
| Credential | Salesforce Platform Identity and Access Management Architect |
| Track | Architect |
| Level in source inventory | Senior |
| Exam code in source inventory | Plat-Arch-203 |
| Price in source inventory | $400 USD |
| Availability | Available |
Exam format, objectives, pricing, and prerequisites can change. Confirm those details in Salesforce’s current exam guide before purchasing or scheduling an exam.
Study overview
🛡️ Secure your perimeter and master the flow of trust across the enterprise.Platform Identity and Access Management Architect
The definitive guide to architecting secure, scalable, and seamless user experiences.
At a Glance
| Category | Details |
|---|---|
| Exam Code | Plat-Arch-203 |
| Duration | 120 Minutes |
| Questions | 60 multiple-choice and 5 unscored |
| Passing Score | 67% |
| Cost | $400 USD |
| Delivery | Proctored (Onsite or Online) |
| Prerequisites | None |
| Recommended Experience | 2+ years of identity/security technology and 1+ years on the Salesforce platform |
Who Should Take This
- Identity Architects who need to design secure, high-performance access management solutions that span multiple platforms and complex system integrations.
- Senior Developers moving into architectural roles who want to master the nuances of federated authentication,
SAML, andOAuthflows. - Security Professionals tasked with ensuring organizational compliance and implementing the principle of least privilege across a Salesforce environment.
- System Architects pursuing the Application or System Architect tracks, as this certification serves as a core pillar for the CTA journey.
What You’ll Prove
This exam goes beyond basic user setup. It validates your ability to translate complex business requirements into a robust identity strategy that balances security with a frictionless user experience. You aren’t just clicking buttons; you are designing the trust fabric of the organization. * You can design end-to-end identity architectures that include both Salesforce-native and third-party systems.
- You can recommend the appropriate
OAuthflow (e.g.,JWT Bearer,Web Server) based on specific integration security and interaction needs. - You can troubleshoot failed
SSOattempts by analyzingSAMLassertions, certificate issues, andMy Domainconfigurations. - You can implement advanced user lifecycle management strategies, including
Just-in-Time (JIT)provisioning andIdentity Connectsynchronization. - You can articulate the trade-offs between different authentication methods and their impact on mobile, community, and internal users.
Exam Outline
| Domain | Weight | What’s Covered |
|---|---|---|
| Identity Management Concepts | 17% | IdP vs SP roles, establishing trust, and user provisioning methods. |
| Accepting Third-Party Identity | 21% | SAML and OAuth for inbound SSO, and social sign-on. |
| Salesforce as an Identity Provider | 17% | Connected Apps, OAuth flows, and outbound SSO. |
| Access Management Best Practices | 15% | Multi-factor authentication (MFA), session security, and auditing. |
| Salesforce Identity | 12% | License types, Identity Connect, and Customer 360 fit. |
| Community (Partner and Customer) | 18% | Experience Cloud authentication and external user management. |
💡 In Notion, convert each domain row into a toggle to nest your study notes underneath.
Suggested Study Path
- Master the Fundamentals by distinguishing between Authentication (who you are) and Authorization (what you can do), and understanding the
IdPvsSPrelationship. - Configure Hand-on Labs in a Developer Edition org or Sandbox. Don’t just read about
SAML; actually set up a functionalSSOflow and break it to see how the error messages look. - Deep Dive into OAuth by mapping every flow to a real-world use case. You should know exactly when to use
JWT(server-to-server) versusWeb Server(user-interactive). - Review Identity Connect documentation. Understand how it integrates with Active Directory for automated provisioning and the role it plays in the overall architecture.
- Study Scenario Questions that force you to choose the “best” solution among several technically possible ones. Focus on trade-offs regarding licensing, security, and maintenance.
Watch Out For
- The IdP/SP Swap: In scenario questions, double-check if Salesforce is acting as the Identity Provider or the Service Provider. Choosing the wrong flow for the direction of trust is a quick way to fail.
- Provisioning Nuances: Know the difference between
JIT(Just-in-Time) andSCIM(System for Cross-domain Identity Management). One is event-driven at login; the other is for continuous synchronization. - OAuth Flow Pitfalls: Don’t default to the
Username-Passwordflow. It is almost never the “architecturally sound” answer in a modern security scenario. - My Domain Requirements: Remember that
My Domainis a non-negotiable prerequisite for almost every identity feature, includingSSOandLightningcomponents.
Resources
- Official Exam Guide
- Architect Journey: Identity and Access Management Trailmix
- Salesforce Identity Documentation
- Trailblazer Community: Ladies Be Architects (IAM Series)
Stop worrying about the login screen and start obsessing over the token exchange. If you can’t explain the difference between a SAML assertion and an OAuth scope, you aren’t ready yet.
Official status sources
Catalog status last verified: 2026-07-19.