A company has many separate AWS accounts with no centralized billing or management. They use Microsoft Azure Active Directory on-premises and want to centralize AWS billing/management, adopt identity federation instead of manual user provisioning, and use temporary credentials rather than long-lived access keys. Which set of steps will meet these goals? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new AWS account to act as the management account. Establish an AWS Organization and invite each existing AWS account to join the organization. Ensure each account accepts the invitation., Deploy AWS IAM Identity Center (AWS Single Sign-On) in the management account. Connect IAM Identity Center to Azure Active Directory and configure it to synchronize users and groups., Create AWS IAM Identity Center permission sets and attach those permission sets to the appropriate IAM Identity Center groups and AWS accounts..
Why this is the answer
Establishing an AWS Organization with a new management account centralizes billing and management across existing AWS accounts. Deploying AWS IAM Identity Center (AWS Single Sign-On) in the management account and connecting it to Azure AD enables identity federation, allowing users to authenticate with their existing Azure AD credentials. Configuring IAM Identity Center to synchronize users and groups from Azure AD eliminates manual user provisioning. Creating IAM Identity Center permission sets and assigning them to groups and accounts ensures users receive temporary credentials and appropriate access across the organization, fulfilling the requirement for temporary credentials over long-lived access keys. Setting account email addresses to a single address does not centralize billing or management, nor does it address identity federation or temporary credentials. Deploying AWS Managed Microsoft AD is unnecessary as the company already uses Azure AD on-premises and IAM Identity Center can integrate directly. Configuring IAM in each account to use AWS Managed Microsoft AD is also incorrect for the same reason.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed