AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A company with employees who need access to multiple AWS accounts wants to provide centralized, single sign-on access using their existing corporate directory credentials, without creating separate IAM users in each account. Which AWS service should the company use?

  1. AAWS Directory Service
  2. BAWS Secrets Manager
  3. CAWS IAM Identity Center
  4. DAmazon Cognito
Show answer & explanation

Correct answer: C. AWS IAM Identity Center

AWS IAM Identity Center (successor to AWS SSO) provides centralized single sign-on access to multiple AWS accounts and applications, integrating with existing identity providers. Secrets Manager stores application secrets, Cognito manages sign-in for customer-facing applications, and Directory Service hosts directories but does not itself provide multi-account SSO.

Why the other options are wrong

  • A. Directory Service hosts a managed directory but doesn't provide the SSO portal itself.
  • B. Secrets Manager stores and rotates secrets like database credentials.
  • D. Cognito is designed for customer-facing app authentication, not workforce SSO across accounts.

AWS IAM Identity Center

A service that provides centralized single sign-on access for workforce users across multiple AWS accounts and business applications.

  • Formerly known as AWS Single Sign-On (SSO)
  • Integrates with external identity providers like Azure AD or Okta
  • Eliminates the need to create individual IAM users in every account

Memory trick: Identity Center is the single front door to every AWS account.

More Security and Compliance questions