A security engineer is setting up SAML 2.0 federation for a multi-account environment. AWS IAM Identity Center is configured as the identity provider (IdP), and IAM roles grant access to the AWS accounts. A federated user reports that authentication fails with the new setup. What is the most operationally efficient way to troubleshoot?
Choose an answer
Tap an option to check your answer.
Correct answer: Review logs from the SAML IdP for errors, and use AWS CloudTrail to confirm which API calls the user attempted..
Why this is the answer
The most operationally efficient way to troubleshoot SAML federation issues is to start with the logs. The SAML IdP (IAM Identity Center in this case) will provide detailed error messages if the initial authentication or assertion process fails, indicating problems with user attributes, SAML response signing, or metadata configuration. Concurrently, AWS CloudTrail logs API calls made within AWS accounts. If a user successfully federates but then encounters permission issues, CloudTrail will show which API calls were denied and why, helping to pinpoint problems with IAM role trust policies or permissions policies. Reviewing logs from the SAML IdP and CloudTrail is a direct approach to identify the root cause of authentication or authorization failures. The IAM policy simulator is useful for testing policies but doesn't show why a live authentication failed. IAM Access Advisor shows past access, not current failures. Recreating the IdP is time-consuming and unnecessary without first diagnosing the problem.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed