A company wants its employees to sign in to the AWS Management Console using their existing credentials stored in an on-premises Microsoft Active Directory. Each employee must get permissions to EC2, S3, and Lambda based on their role. Which solution provides this with the LEAST operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Set up AWS Directory Service for Microsoft Active Directory in AWS and establish a trust with the on-premises Active Directory. Configure IAM roles and trust policies to grant role-based access to AWS resources..
Why this is the answer
The correct solution leverages AWS Directory Service for Microsoft Active Directory (Managed Microsoft AD) to establish a trust relationship with the on-premises Active Directory. This allows employees to use their existing AD credentials for AWS Console access. Managed Microsoft AD integrates seamlessly with IAM, enabling the use of IAM roles and trust policies to grant role-based permissions to AWS resources like EC2, S3, and Lambda. This approach offers the least operational overhead because AWS manages the directory infrastructure, and the trust relationship simplifies identity synchronization and authentication. Using LDAP directly with IAM isn't a native, supported integration for console access. Building a custom identity broker involves significant development and maintenance overhead. Amazon Cognito is primarily for web and mobile application user management and doesn't natively federate with on-premises Active Directory for AWS Console access in this manner without additional complex integrations.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed