AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium

A financial institution is migrating its on-premises applications to AWS. Due to strict regulatory requirements, all access to AWS resources must be authenticated against their existing corporate Active Directory. Furthermore, users should only be granted the minimum necessary permissions based on their job function. Which combination of AWS services should the SysOps administrator use to meet these requirements?

  1. AAWS Directory Service Simple AD for identity, and AWS Organizations Service Control Policies (SCPs) for permissions.
  2. BAWS Directory Service for Microsoft Active Directory (Managed AD) for identity, and IAM roles for permissions.
  3. CAWS Single Sign-On (SSO) for identity, and IAM policies for permissions.
  4. DAWS Identity and Access Management (IAM) users for identity, and AWS Resource Access Manager (RAM) for permissions.
Show answer & explanation

Correct answer: B. AWS Directory Service for Microsoft Active Directory (Managed AD) for identity, and IAM roles for permissions.

AWS Directory Service for Microsoft Active Directory (Managed AD) allows you to integrate your existing on-premises Active Directory with AWS, enabling users to authenticate using their existing credentials. IAM roles are the standard and recommended way to grant temporary, fine-grained permissions to users authenticated through an identity provider like Managed AD, aligning with the principle of least privilege.

Why the other options are wrong

  • A. Simple AD is a standalone directory and doesn't integrate with an existing on-premises AD. SCPs manage permissions at the organizational level, not fine-grained user permissions.
  • C. AWS SSO can integrate with external identity providers, but Managed AD is specifically designed for integrating with Microsoft AD. IAM policies define permissions, but roles are preferred for federated access.
  • D. IAM users are for native AWS identities, not for integrating with an existing corporate Active Directory. RAM shares resources, not manages user permissions.

AWS Identity Federation with AD

Integrates on-premises Active Directory with AWS to allow users to sign in to AWS using their existing corporate credentials and assume IAM roles for access.

  • Uses AWS Directory Service for Microsoft Active Directory.
  • Enables single sign-on (SSO) experience.
  • Grants permissions via IAM roles.

Memory trick: Federate for familiar faces, roles for restricted rights.

More Security and Compliance questions