A company is creating an organization in AWS Organizations. The company needs to integrate user management with an external identity provider (IdP) and centrally manage access to all AWS accounts and applications from the management account. Which solution will meet these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable AWS IAM Identity Center and configure the external IdP as the identity source. Use IAM Identity Center to create permission sets and account assignments..
Why this is the answer
AWS IAM Identity Center (formerly AWS SSO) is the recommended service for centralizing access management across multiple AWS accounts in an AWS Organizations setup. By configuring the external IdP as the identity source, users authenticate through their existing IdP. IAM Identity Center then allows you to create permission sets, which define the access permissions, and assign them to users or groups for specific AWS accounts, fulfilling the requirement for centrally managed access to all accounts and applications. Incorrect options: AWS Directory Service integrates with external IdPs but is primarily for directory-aware workloads and does not offer the same centralized, multi-account access management capabilities as IAM Identity Center. Configuring IAM to trust an external IdP is done per account and does not provide the centralized, multi-account management required by AWS Organizations. Amazon Cognito is primarily for customer-facing applications and user pools, not for centralizing enterprise-level access management across an AWS Organization.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed