Soru

Zorluk: OrtaIdentity Federation and Directory Services

An energy infrastructure company is deploying a multi-account AWS environment managed by AWS Organizations. The company uses Microsoft Entra ID as its central identity provider. The security team requires that cloud engineers be able to sign in to the AWS Management Console and AWS CLI using their existing corporate credentials. Additionally, user access and group memberships must automatically provision and deprovision from Microsoft Entra ID to AWS. Which solution meets these requirements with the least operational overhead?

  1. A
    Manually create individual IAM users with long-term access keys in each AWS account for every cloud engineer, and write a custom synchronization script to update their credentials when they change in Microsoft Entra ID.
  2. Configure AWS IAM Identity Center to federate with Microsoft Entra ID using SAML 2.0, and enable automatic provisioning using the System for Cross-domain Identity Management (SCIM) protocol.Cevap
  3. C
    Set up a SAML 2.0 identity provider individually in IAM for each AWS account, establish trust with Microsoft Entra ID, and create individual IAM users in the management account to distribute long-term AWS CLI credentials.
  4. D
    Configure cloud engineers to log in to the AWS Organizations management account using the root user credentials, and utilize cross-account IAM roles to access member accounts.

Cevap

Configure AWS IAM Identity Center to federate with Microsoft Entra ID using SAML 2.0, and enable automatic provisioning using the System for Cross-domain Identity Management (SCIM) protocol.
Configuring AWS IAM Identity Center to federate with Microsoft Entra ID using SAML 2.0 and enabling automatic provisioning via SCIM satisfies all authentication and synchronization requirements. This configuration delegates credential verification to the corporate identity provider while ensuring that access is automatically terminated in AWS when a user is deprovisioned in Entra ID, minimizing administrative overhead across multiple AWS accounts.

Adım Adım Çözüm

1
Identify the central identity source and single sign-on requirement.
Microsoft Entra ID is the corporate identity source, and AWS IAM Identity Center is selected to centralize multi-account access control.
AWS IAM Identity Center is the modern and recommended service to configure single sign-on across all member accounts in AWS Organizations.
2
Select the correct integration protocol for authentication and directory synchronization.
Configure SAML 2.0 federation for single sign-on and enable the SCIM protocol for identity synchronization.
SAML 2.0 allows federated authentication, while SCIM automates the provisioning and deprovisioning of users and groups from the external IdP without manual overhead.

Anahtar Kavram

AWS IAM Identity Center Federation with SCIM
Bu soruyu puanla