Soru

Zorluk: KolayMulti-Account Management and Governance

An organization needs to implement centralized user access management for its engineering department across a newly created multi-account AWS environment. The security policy mandates that engineers use their existing corporate directory credentials to log in, and no long-term credentials should be distributed.

Which solution should a Solutions Architect implement to meet these governance requirements?

  1. Deploy AWS IAM Identity Center in the organization, integrate it with the corporate directory, and assign the engineers to appropriate permission sets.Cevap
  2. B
    Create individual IAM users in each AWS account for the engineers, configure password policies, and assign access keys.
  3. C
    Create a shared IAM user in the management account with AdministratorAccess, and distribute the root access keys to the engineering team.
  4. D
    Store administrative credentials as plaintext parameters in AWS Systems Manager Parameter Store and configure cross-account sharing.

Cevap

Deploy AWS IAM Identity Center in the organization, integrate it with the corporate directory, and assign the engineers to appropriate permission sets.
Deploying AWS IAM Identity Center allows organizations to centrally manage single sign-on access to all AWS accounts. Integrating it with an external identity provider ensures that engineers can use their existing corporate directory credentials, and temporary security credentials are automatically requested when they access their designated accounts, fulfilling the security policy.

Adım Adım Çözüm

1
Enable and configure AWS IAM Identity Center from the organization's management account.
Centralized single sign-on service is activated across the entire organization.
This establishes a centralized directory and access portal for all member accounts.
2
Integrate AWS IAM Identity Center with the existing corporate directory (e.g., Active Directory or external identity provider).
Users can authenticate using their existing corporate credentials.
This eliminates the need to create new sets of credentials for the engineers.
3
Create permission sets defining the required access levels and assign them to the engineering directory groups in the target accounts.
Engineers gain federated access to target accounts with temporary credentials.
This ensures compliance with the security policy against distributing long-term credentials.

Anahtar Kavram

Centralized Identity Management and Federation in Multi-Account Environments
Bu soruyu puanla