Question 1 · choose 2
A company manages its workforce in an external SAML 2.0 identity provider and uses AWS IAM Identity Center for access to 60 AWS accounts. Employees must sign in with their corporate credentials, and users and groups must be created, updated and removed in Identity Center automatically when they change in the identity provider. Which steps should the company take? (Choose TWO.)
- ACreate an IAM SAML identity provider in each of the 60 member accounts
- BDeploy AD Connector in a shared VPC and point it at the identity provider
- CCreate an Amazon Cognito user pool that federates with the identity provider
- DSet the external IdP as the Identity Center identity source using SAML 2.0
- ETurn on SCIM automatic provisioning between the IdP and Identity Center
Show the answer and why
ACreate an IAM SAML identity provider in each of the 60 member accounts
Incorrect
That is per-account IAM federation, which bypasses Identity Center and provisions nothing.
BDeploy AD Connector in a shared VPC and point it at the identity provider
Incorrect
AD Connector is a gateway to an on-premises Microsoft Active Directory, not to a SAML identity provider.
CCreate an Amazon Cognito user pool that federates with the identity provider
Incorrect
Cognito user pools serve application users, not workforce access to AWS accounts through Identity Center.
DSet the external IdP as the Identity Center identity source using SAML 2.0
Correct
Connecting the external IdP through SAML 2.0 lets users sign in to the AWS access portal with their corporate credentials.
ETurn on SCIM automatic provisioning between the IdP and Identity Center
Correct
SAML cannot query the IdP for users and groups; SCIM provisioning keeps them synchronized in Identity Center.
With an external IdP, SAML handles sign-in and SCIM handles who exists. Users and groups must be provisioned before they can be assigned to accounts.
AWS documentation