Soru

Zorluk: KolayIdentity Federation and Directory Services

An enterprise company wants to grant its employees access to multiple AWS accounts within AWS Organizations. The company uses an external identity provider (IdP) that supports SAML 2.0 to manage its workforce. The company wants to minimize administrative overhead and avoid creating duplicate credentials.

Which solution meets these requirements with the least operational complexity?

  1. Enable AWS IAM Identity Center, connect it to the external identity provider via SAML 2.0, and map corporate groups to AWS permission sets in the target accounts.Cevap
  2. B
    Create individual IAM users in each AWS account for every corporate employee, and write an automation script to rotate their long-term access keys.
  3. C
    Create a single shared IAM user in each AWS account, generate access keys for all employees, and configure policy boundaries on the shared user.
  4. D
    Use the AWS account root user credentials of the Organization management account to perform all daily administrative tasks across all member accounts.

Cevap

Enable AWS IAM Identity Center, connect it to the external identity provider via SAML 2.0, and map corporate groups to AWS permission sets in the target accounts.
Configuring AWS IAM Identity Center with a SAML 2.0 external identity provider enables single sign-on (SSO) across multiple AWS accounts. By mapping corporate groups to AWS permission sets, administrators can grant permissions centrally, eliminating the need to create individual IAM users or credentials in each account.

Adım Adım Çözüm

1
Identify the requirement to manage access across multiple AWS accounts using an existing external Identity Provider (IdP) supporting SAML 2.0.
Determine that federation is required to avoid duplicating credentials and minimize administrative overhead.
Federation allows users to log in using their existing corporate credentials.
2
Evaluate the options for multi-account federation in AWS.
AWS IAM Identity Center is the AWS-recommended service for centralizing access control across AWS Organizations.
It supports SAML 2.0 integration and allows mapping corporate directory groups directly to AWS permission sets without managing individual IAM users.

Anahtar Kavram

AWS IAM Identity Center provides centralized management of SSO access to multiple AWS accounts and SAML applications using an external IdP.
Bu soruyu puanla