Question 1 · choose 1
A company manages its workforce in an external identity provider that supports SAML 2.0 and SCIM. Employees need access to 200 accounts in AWS Organizations. When HR adds a user to a group or removes a user, the change must reach AWS without manual work, and access must be granted by group and account. The company does not want IAM users. Which solution has the LEAST operational overhead?
- ACreate a SAML identity provider and federated IAM roles in each of the 200 accounts, and map the identity provider's groups to the roles
- BConnect the identity provider to AWS Directory Service AD Connector and grant access to the directory groups with IAM policies in each account
- CUse the external provider as the IAM Identity Center identity source with SCIM provisioning, and assign permission sets to groups per account
- DCreate an Amazon Cognito identity pool federated with the provider and give employees temporary credentials for each account through it
Show the answer and why
ACreate a SAML identity provider and federated IAM roles in each of the 200 accounts, and map the identity provider's groups to the roles
Incorrect
IAM SAML federation works, but the provider and roles must be created and kept current in every account, which is far more work than one central configuration.
BConnect the identity provider to AWS Directory Service AD Connector and grant access to the directory groups with IAM policies in each account
Incorrect
AD Connector is a directory gateway that redirects requests to an on-premises Microsoft Active Directory. It does not connect a SAML and SCIM identity provider, and per-account IAM policies would still need to be maintained.
CUse the external provider as the IAM Identity Center identity source with SCIM provisioning, and assign permission sets to groups per account
Correct
IAM Identity Center can use an external identity provider as its identity source and synchronize users and groups automatically over SCIM. Permission sets assigned to groups give access to many accounts from one place.
DCreate an Amazon Cognito identity pool federated with the provider and give employees temporary credentials for each account through it
Incorrect
Cognito identity pools give the users of your own applications temporary credentials. Workforce access to AWS accounts is what IAM Identity Center is for.
"Changes flow in automatically" points to SCIM provisioning, and "many accounts by group" points to IAM Identity Center permission sets.
AWS documentation