A company uses AWS Organizations and AWS IAM Identity Center (AWS Single Sign-On) to manage access across multiple AWS accounts. A security engineer creates a reusable permission set in IAM Identity Center that includes both an AWS managed policy and a customer managed policy. Although the engineer has full administrative permissions in the management account, assigning this permission set to a user who has access to multiple accounts fails. How should the engineer resolve the assignment failure?
Choose an answer
Tap an option to check your answer.
Correct answer: Ensure the customer managed policy exists in every target account where the permission set will be assigned, using the same policy name and permissions in each account..
Why this is the answer
When you create a permission set in IAM Identity Center that includes a customer managed policy, that policy must exist in every AWS account where the permission set is assigned. IAM Identity Center deploys the permission set by creating an IAM role in each target account. If a referenced customer managed policy is missing from an account, the role creation fails for that account, leading to an assignment failure. The policy name and its contents must be identical across all target accounts for successful deployment. Incorrect options: Detaching policies and creating a second permission set is an unnecessary workaround that complicates management and doesn't address the root cause of the missing policy. Resolving conflicts within the policies is good practice but irrelevant to the assignment failure caused by a missing policy. The issue isn't policy conflict but policy existence. Modifying an existing permission set to include both policies would still encounter the same failure if the customer managed policy is not present in all target accounts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed