Soru

Zorluk: KolayMulti-Account Management and Governance

A Solutions Architect is setting up a new multi-account AWS environment using AWS Organizations. The company's security policy requires centralized management of user access across all AWS accounts, allowing employees to log in using their existing corporate credentials. Which approach should the Solutions Architect recommend to meet these requirements securely?

  1. Enable AWS IAM Identity Center in the organization, and integrate it with the corporate identity provider for centralized user access.Cevap
  2. B
    Create individual IAM users in each AWS member account, and generate access keys for each corporate user to authenticate.
  3. C
    Share the credentials of the management account's AWS account root user with all administrators to perform daily operations.
  4. D
    Enable cross-account access by configuring IAM user policies that allow direct login via the management account's root user credentials.

Cevap

Enable AWS IAM Identity Center in the organization, and integrate it with the corporate identity provider for centralized user access.
Enabling AWS IAM Identity Center and integrating it with the corporate identity provider is the AWS-recommended best practice for managing centralized user access across a multi-account organization. It allows employees to use their existing credentials and supports role-based access control with temporary credentials.

Adım Adım Çözüm

1
Identify the primary requirement: centralized management of user access across multiple AWS accounts in an organization using corporate credentials.
Requires a federated single sign-on (SSO) solution.
Centralized federation avoids managing individual credentials per account.
2
Evaluate AWS services suitable for centralized federation across AWS Organizations.
AWS IAM Identity Center provides built-in integration with external identity providers and centralized permission management.
It natively supports multi-account environments under AWS Organizations.
3
Eliminate options that require creating individual IAM users or using root credentials.
Options proposing individual IAM users or root user credentials are secure-practice violations.
They violate the principle of least privilege and represent management overhead.

Anahtar Kavram

Centralized Multi-Account Identity Federation
Tahmini Süre:45s
Bu soruyu puanla