A company uses AWS IAM Identity Center (AWS Single Sign-On) integrated with Active Directory. An admin grants access to a newly created AWS account by assigning the Active Directory Domain Users group, since every employee is a member of that group. When employees attempt to sign in, they are denied access. What action will fix the login failures?
Choose an answer
Tap an option to check your answer.
Correct answer: Fix the Active Directory group's permissions so that IAM Identity Center can read the group's membership..
Why this is the answer
The correct answer is to fix the Active Directory group's permissions. When IAM Identity Center is integrated with Active Directory, it requires specific read permissions to enumerate group memberships. If these permissions are not correctly configured for the Active Directory Domain Users group, IAM Identity Center cannot determine who is a member and therefore denies access, even if users are technically in the group. Creating a separate AD group and adding employees to it (option 1) wouldn't solve the underlying permissions issue; the new group would likely suffer the same problem. Synchronizing time settings (option 2) is generally good practice but unrelated to group membership reading failures. Removing and rejoining the account (option 3) is a drastic step and doesn't address the specific Active Directory permissions needed by IAM Identity Center.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed