AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementEasy
A financial institution is migrating its on-premises applications to AWS. These applications rely heavily on a centralized Microsoft Active Directory for user authentication and authorization. The institution requires a highly available, scalable, and secure directory service that can seamlessly integrate with existing on-premises Active Directory and also provide single sign-on (SSO) capabilities for AWS services and third-party applications. Which AWS service should the institution choose to meet these requirements?
- AAWS IAM Identity Center (formerly AWS SSO)
- BAWS Organizations
- CAmazon Cognito User Pools
- DAWS Directory Service for Microsoft Active Directory (Enterprise Edition)
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Directory Service for Microsoft Active Directory (Enterprise Edition)
AWS Directory Service for Microsoft Active Directory (Enterprise Edition) provides a fully managed, highly available Microsoft Active Directory in the AWS cloud. It allows seamless integration with on-premises Active Directory and supports SSO for AWS services and applications, fulfilling all specified requirements.
Why the other options are wrong
- A. AWS IAM Identity Center is for managing access to AWS accounts and applications, but it relies on an underlying directory service like AWS Managed Microsoft AD or an external IdP.
- B. AWS Organizations is used for consolidating multiple AWS accounts and managing them centrally, not for providing a directory service.
- C. Amazon Cognito User Pools is primarily for customer-facing applications and does not provide the robust enterprise-grade Active Directory features or seamless on-premises integration required.
AWS Managed Microsoft AD
A fully managed, highly available Microsoft Active Directory service in the AWS cloud that supports integration with on-premises AD and SSO.
- Enterprise Edition offers multi-Region replication and higher scale.
- Supports Kerberos, LDAP, and Group Policy.
- Enables seamless domain join for EC2 instances.
Memory trick: Think of managing your company's 'people directory' in the cloud, just like your office directory.