A company manages access with IAM users and groups across AWS accounts in an AWS Organizations organization and uses an external identity provider (IdP) for workforce single sign-on (SSO). The company needs a single management portal to access accounts in the organization, with the external IdP as the federation source. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable AWS IAM Identity Center and configure the external IdP as the identity source..
Why this is the answer
AWS IAM Identity Center (successor to AWS SSO) is the correct solution because it provides a single management portal for accessing multiple AWS accounts within an AWS Organizations organization. It natively supports integration with external identity providers (IdPs) like Okta or Azure AD, allowing users to authenticate through their existing IdP credentials and gain federated access to AWS accounts. This directly addresses the requirement for a single management portal with the external IdP as the federation source. Federation with AWS IAM (without IAM Identity Center) would require configuring individual IdP integrations for each AWS account, which doesn't provide a single management portal. Amazon Verified Permissions is a fine-grained authorization service, not an identity management solution for federated access to AWS accounts. Migrating users to AWS Directory Service would involve creating a new directory, which is not necessary when an external IdP is already in use, and AWS Control Tower is for governance and landing zone setup, not primarily for federated identity management.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed