A company uses Amazon Cognito User Pools for authenticating its mobile application users. The application needs to allow authenticated users to upload images directly to a specific Amazon S3 bucket. Unauthenticated users should have restricted read-only access to a public S3 bucket. Additionally, the application requires fine-grained access control based on user attributes (e.g., premium users can access certain folders). Which AWS service and configuration should be used to achieve this?
- AConfigure Amazon Cognito User Pools with custom attributes and link them to IAM policies for S3 access.
- BUse an IAM role for the mobile application with broad S3 access and handle authorization within the application code.
- CUtilize Amazon Cognito Identity Pools (federated identities) to vend temporary, fine-grained credentials based on authentication status and user attributes.
- DCreate separate IAM users for each mobile application user and assign them individual S3 access policies.
Show answer & explanationAnswer & explanation
Correct answer: C. Utilize Amazon Cognito Identity Pools (federated identities) to vend temporary, fine-grained credentials based on authentication status and user attributes.
Amazon Cognito Identity Pools (federated identities) are designed for this exact use case. They integrate with User Pools (or other identity providers) to vend temporary, limited-privilege AWS credentials to your application users. This allows you to define different IAM roles for authenticated and unauthenticated users, and further refine access using policy variables based on user attributes from the User Pool.
Why the other options are wrong
- A. While User Pools manage attributes, Identity Pools are specifically designed to exchange these attributes for temporary AWS credentials with fine-grained access through IAM policies.
- B. Using a single IAM role for the application with broad S3 access violates the principle of least privilege and does not provide fine-grained control based on user authentication status or attributes.
- D. Creating individual IAM users for each mobile application user is cumbersome, not scalable, and goes against the serverless, temporary credential model of Cognito.
Amazon Cognito Identity Pools (Federated Identities)
Cognito Identity Pools allow you to grant your users (authenticated or unauthenticated) temporary access to AWS services by exchanging tokens from identity providers (like User Pools) for AWS credentials.
- Provides temporary AWS credentials.
- Supports authenticated and unauthenticated access.
- Integrates with User Pools for identity management.
- Enables fine-grained access control using IAM policies and user attributes.
Memory trick: Identity Pools federate users to AWS with fine-grained roles.