Soru

Zorluk: OrtaIdentity Federation and Directory Services

A biotechnology enterprise needs to grant its laboratory researchers single sign-on (SSO) access to multiple AWS accounts and several external third-party SaaS applications. The researchers currently authenticate using an on-premises Active Directory. The proposed architecture must minimize operational overhead, avoid replicating user passwords to the cloud, and enforce centralized access management. Which configuration meets these requirements?

  1. Enable AWS IAM Identity Center, connect it to the on-premises Active Directory using an AD Connector, and integrate both the AWS accounts and the SaaS applications with IAM Identity Center.Cevap
  2. B
    Create individual IAM users in each AWS account for the laboratory researchers, configure their access permissions manually, and instruct them to use these credentials along with their Active Directory logins.
  3. C
    Access the AWS management console using the root user credentials of each AWS account to configure individual SAML 2.0 federation endpoints directly linked to the on-premises Active Directory.
  4. D
    Deploy an authentication portal on Amazon EC2 that queries the on-premises Active Directory, storing the Active Directory service account password as a plain text string parameter in Systems Manager Parameter Store.

Cevap

Enable AWS IAM Identity Center, connect it to the on-premises Active Directory using an AD Connector, and integrate both the AWS accounts and the SaaS applications with IAM Identity Center.
Connecting AWS IAM Identity Center to the on-premises Active Directory via AD Connector provides centralized authentication without replicating password data. Furthermore, IAM Identity Center natively supports single sign-on (SSO) to both AWS accounts and SaaS applications, meeting all design constraints while keeping operational overhead low.

Adım Adım Çözüm

1
Connect on-premises Active Directory to AWS.
Use an AD Connector to redirect directory requests to the on-premises Active Directory without copying password data to AWS.
This satisfies the requirement to avoid replicating user credentials to the cloud.
2
Enable AWS IAM Identity Center.
Configure IAM Identity Center to use the Active Directory connection as its identity source.
This provides a centralized location to manage portal access, single sign-on, and permissions.
3
Integrate target systems.
Assign access to AWS accounts and register third-party SaaS applications within the IAM Identity Center application catalog.
This fulfills the SSO requirement for both cloud infrastructure and external software, minimizing administrative overhead.

Anahtar Kavram

Centralized multi-account and SaaS identity federation using AWS IAM Identity Center connected to on-premises Active Directory via AD Connector.
Tahmini Süre:1m 30s
Bu soruyu puanla