An enterprise is centralizing its multi-account access management using AWS IAM Identity Center. The company wants to federate identities from an external SAML 2.0 identity provider (IdP) and ensure that user accounts and group memberships are automatically synchronized from the IdP. Which of the following configuration steps must be performed to establish this integration? (Select TWO.)
- Configure SAML 2.0 federation in AWS IAM Identity Center by exchanging metadata files between the IdP and AWS, and then enable and configure System for Cross-domain Identity Management (SCIM) in AWS IAM Identity Center and the IdP.Cevap
- Create permission sets in AWS IAM Identity Center to define access levels, and assign these permission sets to the synchronized groups and users for the target AWS accounts in the AWS Organization.Cevap
- CDefine a Service Control Policy (SCP) at the root level of AWS Organizations to grant access to the synchronized groups, allowing member accounts to inherit access permissions automatically.
- DIn each target AWS account, configure a custom IAM role with a trust policy that specifies the IdP as the principal and allows the 'sts:AssumeRole' action, then assign this role directly to the external directory groups.
Cevap
Configuring SAML 2.0 federation and SCIM in AWS IAM Identity Center, and creating permission sets to assign to synchronized groups in the target accounts.
To establish federated access and automated user/group provisioning using AWS IAM Identity Center, the solutions architect must configure SAML 2.0 federation (by exchanging metadata between AWS and the IdP) and enable SCIM. The SCIM endpoint and access token allow the IdP to push identity synchronization. Furthermore, the administrator must define permission sets in AWS IAM Identity Center and assign them to the synchronized users or groups for the specific target AWS accounts.
Adım Adım Çözüm
Anahtar Kavram
Centralized multi-account identity federation and provisioning using AWS IAM Identity Center and SCIM.
Tahmini Süre:2m 0s