AD0-E907 · Question #55
Which statement is true about auto-provisioning users in Workfront?
The correct answer is B. It relies on SAML attributes for group assignment. Auto-provisioning in Workfront uses SAML (Security Assertion Markup Language) attributes passed from your identity provider (IdP) to automatically assign users to groups, job roles, and access levels during single sign-on - no manual intervention needed, making B correct. Why…
Question
Which statement is true about auto-provisioning users in Workfront?
Options
- AIt requires manual approval for each user
- BIt relies on SAML attributes for group assignment
- CIt automatically assigns admin privileges
- DIt disables existing user accounts
How the community answered
(20 responses)- A5% (1)
- B70% (14)
- C10% (2)
- D15% (3)
Explanation
Auto-provisioning in Workfront uses SAML (Security Assertion Markup Language) attributes passed from your identity provider (IdP) to automatically assign users to groups, job roles, and access levels during single sign-on - no manual intervention needed, making B correct.
Why the distractors are wrong:
- A is incorrect because auto-provisioning's entire purpose is to eliminate manual approval - users are created and configured automatically on first login.
- C is incorrect because admin privileges are not automatically granted; access levels are mapped from SAML attributes, which typically reflect least-privilege roles.
- D is incorrect because auto-provisioning creates or updates user accounts - it does not disable them. Deactivation is a separate, deliberate action.
Memory tip: Think of SAML as a "passport stamp" - when a user arrives at Workfront via SSO, the IdP's SAML attributes act as the stamp that tells Workfront exactly which group to put them in, automatically.
Topics
Community Discussion
No community discussion yet for this question.