AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementEasy

A company is migrating its on-premises applications to AWS. These applications rely heavily on Microsoft Active Directory for user authentication and group-based access control. The company wants to minimize changes to its existing application code and administrative processes. They also require secure, high-availability integration with their AWS resources. Which AWS service is best suited for this requirement?

  1. AAmazon Cognito User Pools with custom authentication.
  2. BAWS Directory Service for Microsoft Active Directory (Managed Microsoft AD).
  3. CAWS Identity and Access Management (IAM) with SAML federation.
  4. DAWS Cloud Directory for hierarchical data storage.
Show answer & explanation

Correct answer: B. AWS Directory Service for Microsoft Active Directory (Managed Microsoft AD).

AWS Directory Service for Microsoft Active Directory (Managed Microsoft AD) provides a fully managed, highly available Microsoft Active Directory in the AWS Cloud. It allows seamless integration with existing on-premises AD and enables applications that rely on standard AD features to function without modification, making it ideal for the given scenario.

Why the other options are wrong

  • A. Amazon Cognito User Pools are for customer identity and access management for web/mobile apps, not for enterprise applications that rely on Microsoft AD for authentication and group services.
  • C. IAM with SAML federation can integrate with AD, but it's primarily for federating users to AWS services. It doesn't provide a full AD environment for applications that *rely* on AD features.
  • D. AWS Cloud Directory is a hierarchical data store for application development, not a Microsoft Active Directory service for user authentication and group management.

AWS Directory Service for Microsoft Active Directory

A fully managed service that hosts Microsoft Active Directory in the AWS Cloud, enabling seamless integration with existing on-premises AD and AD-aware applications.

  • Managed, highly available Microsoft AD.
  • Supports standard AD features (GPO, Kerberos, LDAP).
  • Enables seamless hybrid identity with on-premises AD.
  • Allows AD-aware applications to run without modification.

Memory trick: Managed AD extends your on-prem AD to AWS.

More Domain 4: Identity and Access Management questions