After initial setup of AWS IAM Identity Center, what should be done next so employees sign in with their existing Active Directory credentials from an external SAML IdP and AD groups are provisioned into IAM?
Choose an answer
Tap an option to check your answer.
Correct answer: Set the identity source to the external SAML identity provider and enable automatic provisioning of users and groups using the SCIM protocol..
Why this is the answer
The correct answer is to set the identity source to the external SAML identity provider and enable automatic provisioning of users and groups using the SCIM protocol. This is because IAM Identity Center supports external SAML 2.0 identity providers for authentication, allowing employees to use their existing Active Directory credentials. For automatic provisioning of users and groups from an external identity provider into IAM Identity Center, the System for Cross-domain Identity Management (SCIM) protocol is used. Using AWS Directory Service or an AD Connector as the identity source would integrate with Active Directory directly, but the question specifies an external SAML IdP. While SAML is used for authentication, SCIM is specifically for provisioning users and groups, making the option that mentions SAML for provisioning incorrect.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed