AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementEasy
A company is migrating its on-premises applications to AWS. These applications rely heavily on Microsoft Active Directory for user authentication and group-based access control. The company wants to minimize changes to its existing application code and administrative processes. They also require secure, high-availability integration with their AWS resources. Which AWS service is best suited for this requirement?
- AAmazon Cognito User Pools with custom authentication.
- BAWS Directory Service for Microsoft Active Directory (Managed Microsoft AD).
- CAWS Identity and Access Management (IAM) with SAML federation.
- DAWS Cloud Directory for hierarchical data storage.
Show answer & explanationAnswer & explanation
Correct answer: B. AWS Directory Service for Microsoft Active Directory (Managed Microsoft AD).
AWS Directory Service for Microsoft Active Directory (Managed Microsoft AD) provides a fully managed, highly available Microsoft Active Directory in the AWS Cloud. It allows seamless integration with existing on-premises AD and enables applications that rely on standard AD features to function without modification, making it ideal for the given scenario.
Why the other options are wrong
- A. Amazon Cognito User Pools are for customer identity and access management for web/mobile apps, not for enterprise applications that rely on Microsoft AD for authentication and group services.
- C. IAM with SAML federation can integrate with AD, but it's primarily for federating users to AWS services. It doesn't provide a full AD environment for applications that *rely* on AD features.
- D. AWS Cloud Directory is a hierarchical data store for application development, not a Microsoft Active Directory service for user authentication and group management.
AWS Directory Service for Microsoft Active Directory
A fully managed service that hosts Microsoft Active Directory in the AWS Cloud, enabling seamless integration with existing on-premises AD and AD-aware applications.
- Managed, highly available Microsoft AD.
- Supports standard AD features (GPO, Kerberos, LDAP).
- Enables seamless hybrid identity with on-premises AD.
- Allows AD-aware applications to run without modification.
Memory trick: Managed AD extends your on-prem AD to AWS.