AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium

A company is migrating its on-premises directory services to AWS and needs a managed solution for user authentication and authorization. The solution must support multi-factor authentication (MFA) and integrate with existing enterprise applications that use LDAP. The security team also requires the ability to apply fine-grained access control to AWS resources based on group memberships. Which AWS service should the company use to meet these requirements?

  1. AAWS Directory Service for Microsoft Active Directory (Standard Edition)
  2. BAWS IAM Identity Center (formerly AWS SSO)
  3. CAWS Managed Microsoft AD
  4. DAmazon Cognito User Pools
Show answer & explanation

Correct answer: C. AWS Managed Microsoft AD

AWS Managed Microsoft AD provides a fully managed, highly available Microsoft Active Directory. It supports standard AD features including LDAP, group-based access control for AWS resources, and integrates with existing on-premises AD through a trust relationship, which is crucial for hybrid environments and enterprise applications. It also supports MFA.

Why the other options are wrong

  • A. AWS Directory Service for Microsoft Active Directory (Standard Edition) is an older naming convention. The current fully managed Microsoft AD service is AWS Managed Microsoft AD. Standard Edition has limitations compared to Enterprise.
  • B. AWS IAM Identity Center (formerly AWS SSO) is an identity management service that simplifies access to AWS accounts and applications. While it integrates with AD, it's not the managed AD service itself. It provides a single sign-on experience but doesn't replace the need for a managed AD for LDAP-based applications or direct AD features.
  • D. Amazon Cognito User Pools is primarily a customer identity and access management (CIAM) service for web and mobile applications, not a managed enterprise directory service that supports LDAP for existing enterprise applications.

AWS Managed Microsoft AD

A fully managed, highly available Microsoft Active Directory hosted in AWS, enabling seamless integration with on-premises AD and support for AD-dependent applications.

  • Provides a real Microsoft Active Directory.
  • Supports LDAP, Kerberos, DNS, Group Policy.
  • Integrates with on-premises AD via trust relationships.
  • Enables fine-grained access control to AWS resources.

Memory trick: For your old AD, Managed AD is the key, in the cloud, happily.

More Domain 4: Identity and Access Management questions