AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementEasy

A financial institution is migrating its on-premises applications to AWS. These applications rely heavily on a centralized Microsoft Active Directory for user authentication and authorization. The institution requires a highly available, scalable, and secure directory service that can seamlessly integrate with existing on-premises Active Directory and also provide single sign-on (SSO) capabilities for AWS services and third-party applications. Which AWS service should the institution choose to meet these requirements?

  1. AAWS IAM Identity Center (formerly AWS SSO)
  2. BAWS Organizations
  3. CAmazon Cognito User Pools
  4. DAWS Directory Service for Microsoft Active Directory (Enterprise Edition)
Show answer & explanation

Correct answer: D. AWS Directory Service for Microsoft Active Directory (Enterprise Edition)

AWS Directory Service for Microsoft Active Directory (Enterprise Edition) provides a fully managed, highly available Microsoft Active Directory in the AWS cloud. It allows seamless integration with on-premises Active Directory and supports SSO for AWS services and applications, fulfilling all specified requirements.

Why the other options are wrong

  • A. AWS IAM Identity Center is for managing access to AWS accounts and applications, but it relies on an underlying directory service like AWS Managed Microsoft AD or an external IdP.
  • B. AWS Organizations is used for consolidating multiple AWS accounts and managing them centrally, not for providing a directory service.
  • C. Amazon Cognito User Pools is primarily for customer-facing applications and does not provide the robust enterprise-grade Active Directory features or seamless on-premises integration required.

AWS Managed Microsoft AD

A fully managed, highly available Microsoft Active Directory service in the AWS cloud that supports integration with on-premises AD and SSO.

  • Enterprise Edition offers multi-Region replication and higher scale.
  • Supports Kerberos, LDAP, and Group Policy.
  • Enables seamless domain join for EC2 instances.

Memory trick: Think of managing your company's 'people directory' in the cloud, just like your office directory.

More Domain 4: Identity and Access Management questions