AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A company with employees who need access to multiple AWS accounts wants to provide centralized, single sign-on access using their existing corporate directory credentials, without creating separate IAM users in each account. Which AWS service should the company use?
- AAWS Directory Service
- BAWS Secrets Manager
- CAWS IAM Identity Center
- DAmazon Cognito
Show answer & explanationAnswer & explanation
Correct answer: C. AWS IAM Identity Center
AWS IAM Identity Center (successor to AWS SSO) provides centralized single sign-on access to multiple AWS accounts and applications, integrating with existing identity providers. Secrets Manager stores application secrets, Cognito manages sign-in for customer-facing applications, and Directory Service hosts directories but does not itself provide multi-account SSO.
Why the other options are wrong
- A. Directory Service hosts a managed directory but doesn't provide the SSO portal itself.
- B. Secrets Manager stores and rotates secrets like database credentials.
- D. Cognito is designed for customer-facing app authentication, not workforce SSO across accounts.
AWS IAM Identity Center
A service that provides centralized single sign-on access for workforce users across multiple AWS accounts and business applications.
- Formerly known as AWS Single Sign-On (SSO)
- Integrates with external identity providers like Azure AD or Okta
- Eliminates the need to create individual IAM users in every account
Memory trick: Identity Center is the single front door to every AWS account.