A company uses an external identity provider and wants employees to access AWS accounts and services without creating separate AWS credentials. Which AWS service enables this capability?
Choose an answer
Tap an option to check your answer.
Correct answer: AWS IAM Identity Center.
Why this is the answer
AWS IAM Identity Center (formerly AWS Single Sign-On) enables centralized management of access to multiple AWS accounts and cloud applications. It integrates with external identity providers (IdPs) like Okta or Azure AD, allowing users to sign in once with their existing corporate credentials and access AWS resources without creating separate AWS IAM users. AWS Directory Service provides managed Microsoft Active Directory or AD Connector, but doesn't directly handle federated access from external IdPs for AWS accounts. Amazon Cognito focuses on user authentication and authorization for web and mobile applications, not enterprise-wide AWS account access. AWS Resource Access Manager (AWS RAM) helps share resources between AWS accounts, but it's not an identity management service.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed