An enterprise is consolidating its billing and resource management under AWS Organizations. The security team wants to establish centralized access control so that employees can sign in using their existing corporate credentials and access their assigned AWS accounts without managing separate passwords. Which of the following is the most secure and operationally efficient method to achieve this goal?
- Configure AWS IAM Identity Center integrated with the enterprise's corporate identity provider.Cevap
- BCreate individual IAM users with long-term credentials in each member account for every employee.
- CDistribute the AWS account root user credentials of each member account to the respective employees.
- DGenerate a single administrative IAM user in the management account and share the credentials with all employees.
Cevap
Configure AWS IAM Identity Center integrated with the enterprise's corporate identity provider.
The correct option is configuring AWS IAM Identity Center integrated with the enterprise's corporate identity provider. This approach centralizes permissions management and integrates directly with the existing corporate identity store, eliminating the need to manage individual IAM credentials in multiple member accounts.
Adım Adım Çözüm
Anahtar Kavram
Centralized multi-account access control via AWS IAM Identity Center
Tahmini Süre:45s