Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium
A company is migrating a critical legacy application to a cloud-native architecture. The application currently relies on a centralized, on-premises directory service for user authentication and authorization. The new cloud environment needs to integrate with this existing directory service without replicating user credentials to the cloud provider's IAM system. Which identity management approach is MOST suitable for this scenario?
- ACloud Provider IAM with local user creation.
- BSynchronizing users and passwords to the cloud provider's directory.
- CIdentity Federation using SAML or OpenID Connect.
- DImplementing a separate, isolated IAM system in the cloud.
Show answer & explanationAnswer & explanation
Correct answer: C. Identity Federation using SAML or OpenID Connect.
Identity Federation allows the cloud application to trust an external identity provider (the existing on-premises directory service) for authentication, without needing to replicate or store user credentials in the cloud. Protocols like SAML or OpenID Connect facilitate this trust relationship.
Why the other options are wrong
- A. This would require creating new user accounts in the cloud, which does not meet the requirement of integrating with the existing directory service without replication.
- B. Synchronizing users and passwords contradicts the requirement of not replicating user credentials to the cloud provider's IAM system and introduces additional security risks.
- D. Implementing a separate, isolated IAM system would create a new silo of identities, not integrating with the existing on-premises directory.
Identity Federation
A system that allows users to authenticate once with a trusted identity provider (IdP) and then gain access to multiple service providers (SPs) without re-authenticating. It establishes a trust relationship between domains.
- Single Sign-On (SSO) capability.
- Reduces credential sprawl and management overhead.
- Commonly uses protocols like SAML, OpenID Connect.
Memory trick: Let your home ID card open cloud doors, no need for a new cloud passport.