An organization uses AWS Organizations with multiple AWS accounts and wants centralized user and permission management integrated with its on-premises Active Directory. IAM Identity Center (SSO) is enabled and Direct Connect exists. Which solution is the most operationally efficient to integrate the on-premises AD with IAM Identity Center?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an AD Connector that connects to the on-premises Active Directory and configure the AD Connector as IAM Identity Center’s identity source; then create permission sets and assign groups..
Why this is the answer
The correct answer is to create an AD Connector. AD Connector is a directory gateway that redirects directory requests to your on-premises Active Directory without caching any information in the cloud. This allows IAM Identity Center (SSO) to authenticate users directly against your existing on-premises AD, leveraging your current user and group management. This is the most operationally efficient solution as it avoids synchronization or replication, maintaining a single source of truth for identities. Creating a Simple AD and establishing a forest trust is more complex and introduces another directory to manage. Deploying a domain controller on EC2 is also more complex and less efficient than AD Connector, requiring you to manage the EC2 instance. Using IAM Identity Center’s built-in directory and copying users would require manual synchronization, which is not operationally efficient.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed