A company needs a scalable, native AWS solution for multi-account authentication and authorization without adding user-managed infrastructure. AWS Organizations (all features) and AWS IAM Identity Center (AWS Single Sign-On) are already enabled. What additional steps should the security engineer take?
Choose an answer
Tap an option to check your answer.
Correct answer: Use the IAM Identity Center default directory to create users and groups for all employees who need AWS access. Assign groups to AWS accounts and link them to permission sets based on job function and access needs. Direct users to the IAM Identity Center user portal..
Why this is the answer
The correct answer leverages AWS IAM Identity Center's native capabilities for centralized multi-account authentication and authorization, which is ideal for a scalable, serverless solution. By using the IAM Identity Center default directory, you create users and groups directly within IAM Identity Center. These groups are then assigned to AWS accounts and linked to permission sets, which define the specific IAM roles and permissions users will assume in those accounts. This approach eliminates user-managed infrastructure and provides a single sign-on experience through the IAM Identity Center user portal. The other options are incorrect because: Using AD Connector or AWS Directory Service for Microsoft Active Directory introduces additional infrastructure or dependencies that the question explicitly aims to avoid ("without adding user-managed infrastructure"). Linking IAM Identity Center groups to existing IAM users in each account is not the recommended or most scalable practice; IAM Identity Center is designed to provision roles via permission sets directly.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed