AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium

A company is migrating a legacy application to AWS. The application uses a custom identity provider (IdP) for authentication and authorization. The security team needs to integrate this IdP with AWS to allow users to securely access AWS resources without storing AWS credentials in the IdP. Which AWS service should be used to achieve this federated access?

  1. AAmazon Cognito User Pools with custom authentication.
  2. BAWS Directory Service for Microsoft Active Directory.
  3. CAWS Single Sign-On (SSO) with SAML 2.0.
  4. DAWS Identity and Access Management (IAM) roles with trust policies.
Show answer & explanation

Correct answer: D. AWS Identity and Access Management (IAM) roles with trust policies.

Federation with a custom IdP is achieved by configuring IAM roles with trust policies that specify the external IdP as a trusted entity. Users authenticate with the IdP, which then issues SAML assertions or OIDC tokens that AWS IAM can consume to grant temporary credentials tied to a specific role, allowing access to AWS resources without storing long-term AWS credentials in the IdP.

Why the other options are wrong

  • A. Cognito User Pools are for customer identity and access management (CIAM) for web/mobile apps, not for federating enterprise users from a custom IdP to AWS accounts.
  • B. AWS Directory Service provides managed Active Directory, not a general solution for integrating custom identity providers.
  • C. AWS SSO (now IAM Identity Center) simplifies access to multiple accounts but primarily integrates with common identity sources like AD or Okta, or its own directory, not a generic 'custom IdP' directly in the same way as raw IAM federation.

IAM Identity Federation

IAM Identity Federation allows external identities (e.g., from corporate directories, social identity providers) to access AWS resources without creating IAM users for each person.

  • Uses temporary security credentials.
  • Supports SAML 2.0, OpenID Connect (OIDC), and custom federation.
  • Leverages IAM roles with trust policies.
  • Enhances security by eliminating long-term credentials.

Memory trick: Federation: Trust an IdP to Give Temporary Role Keys.

More Security and Compliance questions