A DevOps engineer must ensure that every user who signs in to the AWS Management Console is authenticated via the company's corporate identity provider (IdP). The company uses AWS Organizations. Which combination of steps will enforce this requirement? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS IAM Identity Center (AWS SSO) and configure SAML 2.0 federation with the corporate IdP., Create a Service Control Policy in AWS Organizations that denies IAM users the ability to create passwords for console sign-in..
Why this is the answer
To enforce authentication via the corporate IdP, two key steps are needed. First, configuring AWS IAM Identity Center (AWS SSO) with SAML 2.0 federation allows users to sign in to AWS using their existing corporate credentials. This centralizes identity management and provides single sign-on access to AWS accounts. Second, a Service Control Policy (SCP) in AWS Organizations can deny IAM users the ability to create passwords for console sign-in. This SCP prevents users from bypassing the corporate IdP by creating local IAM user credentials, ensuring all console access goes through the federated identity. GuardDuty is a threat detection service and does not manage authentication or block specific sign-in methods. Creating a permissions boundary in IAM Identity Center is not the correct mechanism to deny password-based sign-in for IAM users; SCPs are designed for organization-wide restrictions. Creating IAM groups in the management account does not enforce federated authentication; it's for permission management within accounts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed