Valid Identity-and-Access-Management-Architect Dumps shared by EduDump.com for Helping Passing Identity-and-Access-Management-Architect Exam! EduDump.com now offer the newest Identity-and-Access-Management-Architect exam dumps, the EduDump.com Identity-and-Access-Management-Architect exam questions have been updated and answers have been corrected get the newest EduDump.com Identity-and-Access-Management-Architect dumps with Test Engine here:
Universal Containers is creating a mobile application that will be secured by Salesforce Identity using the OAuth 2.0 user-agent flow. Application users will authenticate using username and password. They should not be forced to approve API access in the mobile app or reauthenticate for 3 months. Which two connected app options need to be configured to fulfill this use case? Choose 2 answers
Correct Answer: C,D
For a mobile app using the user-agent flow, two connected-app controls work together when the business wants a long-lived session without repeated approval prompts. First, the app should be set to Admin Approved Users Are Pre-Authorized so users are not asked to approve API access inside the mobile experience. Second, the refresh-token policy should be configured for the required lifetime, such as three months, so the app can keep renewing access without forcing the user to log in again. A session timeout controls the UI session but not the refresh-token lifecycle in the same way. The architectural point is that user consent suppression and durable reauthentication behavior are governed by separate connected-app policies. This is why options C, D work together as the correct solution.