Soru

Zorluk: OrtaIdentity Federation and Directory Services

An online education platform is migrating its core learning management system (LMS) to AWS. The platform has a multi-account structure managed under AWS Organizations. The company wants to enable its employees to log in to the AWS Management Console across all accounts using their existing corporate credentials, which are managed in an on-premises Microsoft Active Directory. The solutions architect needs to design a solution that minimizes administrative overhead, avoids duplicating user credentials or password hashes in the cloud, and utilizes modern AWS best practices. Which combination of actions should the solutions architect recommend? (Select two.)

  1. Configure AWS Directory Service AD Connector to establish a connection with the on-premises Microsoft Active Directory.Cevap
  2. Enable AWS IAM Identity Center and configure it to use the AD Connector directory as the identity source.Cevap
  3. C
    Create individual IAM users in each AWS account for every corporate employee and configure a custom synchronization script to duplicate passwords daily.
  4. D
    Use the AWS account root user of each member account to configure SAML 2.0 identity provider relationships with the on-premises Active Directory.

Cevap

Configure AWS Directory Service AD Connector to connect to the on-premises Microsoft Active Directory, and enable AWS IAM Identity Center with the AD Connector directory specified as the identity source.
The correct solution involves configuring the AWS Directory Service AD Connector and enabling AWS IAM Identity Center. AD Connector operates as a proxy to redirect sign-in requests to on-premises Active Directory domain controllers without synchronizing or storing password hashes in AWS. Integrating AD Connector with AWS IAM Identity Center allows users to federate into their respective AWS accounts within AWS Organizations using their corporate credentials, providing a seamless single sign-on experience with minimal administrative overhead.

Adım Adım Çözüm

1
Identify directory integration requirements
Determine that the customer requires on-premises Active Directory integration without replicating user credentials to AWS, while keeping administrative overhead low.
This rules out solutions requiring directory synchronization or trust relationships that cache database information in the cloud.
2
Select the directory gateway service
Select AD Connector to proxy authentication requests back to the on-premises Active Directory domain controllers.
AD Connector does not store or replicate user credentials, fulfilling the requirement of keeping passwords on-premises.
3
Select and configure the identity federation service
Enable AWS IAM Identity Center in the Organizations management account and connect it to the Active Directory using the AD Connector.
This establishes a centralized single sign-on portal for all accounts in the organization, aligning with modern AWS security best practices and minimizing administration compared to legacy manual SAML configurations.

Anahtar Kavram

Active Directory Federation with AWS IAM Identity Center via AD Connector
Tahmini Süre:2m 0s
Bu soruyu puanla