An organization uses AWS Control Tower and wants to centralize identity by federating AWS IAM Identity Center with an external SAML 2.0 identity provider. What items must the SysOps administrator have available before connecting the external IdP? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: A copy of the SAML metadata for the IAM Identity Center (the service provider metadata)., The identity provider’s SAML metadata, including its public X.509 certificate..
Why this is the answer
To federate AWS IAM Identity Center with an external SAML 2.0 identity provider (IdP), a trust relationship must be established between the two services. This requires exchanging metadata. The SysOps administrator needs the SAML metadata from IAM Identity Center (the service provider metadata) to configure the external IdP, informing it how to send authentication responses back to AWS. Conversely, the administrator also needs the external IdP's SAML metadata, which includes its public X.509 certificate, to configure IAM Identity Center. This metadata allows IAM Identity Center to validate the authenticity of the SAML assertions received from the IdP. The IP address of the identity provider is not directly used for SAML configuration. Root account credentials are not required for this specific task, and administrator-level access in member accounts is not necessary for configuring the central identity provider.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed