Soru

Zorluk: OrtaIdentity Federation and Directory Services

A logistics and supply chain enterprise is migrating its core applications to a multi-account AWS environment managed by AWS Organizations. The company's corporate identity store is located on-premises in a Microsoft Active Directory (AD) domain. The security policy requires that users authenticate using their existing corporate credentials, without duplicating any user credentials in the cloud. The solution must also minimize administrative overhead.

Which combination of actions should a Solutions Architect recommend to meet these requirements? (Select two.)

  1. Deploy an Active Directory Connector (AD Connector) in the AWS VPC with network connectivity to the on-premises directory.Cevap
  2. Configure AWS IAM Identity Center to use AWS Directory Service as its identity source to enable single sign-on access to the AWS accounts.Cevap
  3. C
    Create individual IAM users with long-term credentials in each member account for every enterprise directory user.
  4. D
    Deploy AWS Managed Microsoft Active Directory in the cloud and configure a two-way forest trust with the on-premises directory, then create matching IAM users.
  5. E
    Configure AWS IAM Identity Center to map administrative Active Directory groups directly to the AWS account root user credentials for daily administrative operations.

Cevap

Deploy an Active Directory Connector (AD Connector) in the AWS VPC with network connectivity to the on-premises directory, and configure AWS IAM Identity Center to use AWS Directory Service as its identity source.
Deploying an Active Directory Connector (AD Connector) redirecting requests to the on-premises Active Directory avoids credential caching or replication in the cloud. Configuring AWS IAM Identity Center to use AWS Directory Service connects this proxy gateway to your AWS Organizations structure, enabling centralized single sign-on access to all member accounts with minimal management effort.

Adım Adım Çözüm

1
Establish secure network connectivity between the AWS VPC and the on-premises network.
A Site-to-Site VPN or AWS Direct Connect connection is configured, allowing low-latency secure IP communication.
This setup allows the AD Connector in AWS to reach the on-premises Active Directory domain controllers.
2
Deploy an AD Connector using AWS Directory Service.
The AD Connector acts as a directory gateway, proxying authentication requests without replicating AD data in the cloud.
This satisfies the business requirement of not duplicating user credentials in the cloud.
3
Configure AWS IAM Identity Center to use AWS Directory Service as the identity source.
IAM Identity Center integrates with the AD Connector, enabling centralized single sign-on (SSO) and permissions assignment to AWS Organizations accounts.
This minimizes administrative overhead by allowing group-based AWS access assignment using existing AD identities.

Anahtar Kavram

Federating an on-premises Microsoft Active Directory with AWS IAM Identity Center using AD Connector to enable centralized SSO without credential replication.
Bu soruyu puanla