Configure, operate, delegate, and decommission administrator accounts in your
Salesforce Government Cloud Plus org following FedRAMP-aligned best practices. These procedures
cover the full account lifecycle—from adjusting privileges and setting up delegate admins to
deactivating departed users and freezing accounts when immediate deactivation is not
possible.
Required Editions
Available in: Enterprise and Unlimited Editions
Version
1.0
Last Updated
May 2026
Configure Administrator Account Permissions
To view and modify the permissions assigned to an admin account:
From Setup, in the Quick Find box, type Users,
then select Users.
Locate the admin you want to modify.
Click the admin's name to open their user detail page.
Click Edit, then change their Profile or
Permission Sets to adjust privileges.
Save your work.
Define Delegate Administrators
To grant limited administrative permissions to users
who are not full admins:
From Setup, in the Quick Find box, type Delegated
Administration, then select Delegated Administration and
click New.
Select or create a delegated group.
To allow group users to log in as users in the role hierarchy they administer, select
Enable Group for Login Access.
Save your work.
For each related list, click Add to define the delegated group
details.
Deactivate Administrator Accounts
You can deactivate users, but not delete them.
Users can own records, belong to groups, and serve on teams. Deactivating a user affects all
associated records and processes. After an admin leaves the organization, deactivate their
account immediately to remove access.
From Setup, in the Quick Find box, type Users,
then select Users.
Locate the admin you want to deactivate.
Click Edit next to their name.
Uncheck the Active checkbox.
Save your work.
Note Deactivated users remain in the system as inactive records. This preserves records,
groups, and teams associated with the user.
Freeze Accounts
Use this procedure
when you cannot immediately deactivate an account—for example, when the user is referenced in a
custom hierarchy field. Freezing blocks login access without fully deactivating the account.
From Setup, in the Quick Find box, type Users,
then select Users.
Click the username of the account you want to freeze.
Click Freeze to block login access, or
Unfreeze to restore access.
Note Freezing is a temporary measure. Complete the deactivation process as soon as the
blocking dependency is resolved.
Løste denne artikel dit problem?
Giv os besked, så vi kan forbedre os!
Indlæser
Salesforce Help | Article
Cookie Consent Manager
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.