A company is establishing many AWS accounts under a single AWS Organizations environment and needs a centralized login solution that integrates with AWS Organizations and a third-party SAML 2.0 identity provider. What is the recommended approach for centrally managing sign-in and permissions across all accounts?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable and configure AWS Single Sign-On (AWS SSO) and connect it to the third-party SAML IdP..
Why this is the answer
AWS Single Sign-On (AWS SSO) is the recommended service for centrally managing access to multiple AWS accounts within an AWS Organizations environment. It integrates directly with AWS Organizations, allowing you to assign permissions to users and groups across all accounts from a single place. AWS SSO also natively supports integration with external SAML 2.0 identity providers, making it ideal for leveraging an existing IdP for authentication. Setting up an Amazon Cognito user pool is for managing user directories for your own applications, not for central AWS account access. Creating SAML federation in each account separately is a manual, unscalable approach that defeats the purpose of centralized management. Directly integrating the third-party IdP with AWS Organizations is not a supported feature; AWS Organizations manages accounts, not identity federation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed