A company using AWS Organizations has more than 100 AWS accounts and plans to add more. The company also uses an external corporate identity provider (IdP). The company must provide users with role-based access to these accounts while maximizing scalability and operational efficiency. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable AWS IAM Identity Center. Integrate IAM Identity Center with the company’s existing IdP. Create permission sets for the required access patterns and assign them to users and accounts as needed..
Why this is the answer
AWS IAM Identity Center (formerly AWS SSO) is the most scalable and operationally efficient solution for managing access across multiple AWS accounts, especially with an external IdP. It centralizes user authentication and authorization, allowing you to create permission sets once and apply them to multiple accounts and users. Integrating with the existing IdP streamlines user management. Creating dedicated IAM users in each account is not scalable or efficient for 100+ accounts. Deploying an IAM role in a central identity account and then creating roles in each account that trust the central account adds unnecessary complexity and management overhead compared to IAM Identity Center. Creating IAM roles in each account with a trust relationship to the IdP is also not scalable for a large number of accounts and users, as it requires individual role creation and management per account.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed