A global company is deploying a new web application that needs to authenticate users from various social identity providers (e.g., Facebook, Google) and corporate directories (e.g., SAML 2.0). After authentication, the application needs to grant these users temporary, limited-privilege access to AWS resources (e.g., upload files to S3). Which combination of AWS services should the developer use to fulfill both authentication and authorization requirements?
- AAWS Directory Service for authentication and AWS Organizations for authorization.
- BAWS IAM for authentication and S3 bucket policies for authorization.
- CAmazon Cognito User Pools for authentication and Amazon Cognito Identity Pools for authorization.
- DAmazon Cognito Identity Pools for authentication and AWS Lambda for authorization logic.
Show answer & explanationAnswer & explanation
Correct answer: C. Amazon Cognito User Pools for authentication and Amazon Cognito Identity Pools for authorization.
Cognito User Pools handle user authentication (from social, SAML, etc.) and manage user directories. Cognito Identity Pools then exchange the authenticated user's credentials for temporary AWS credentials, allowing them to access specified AWS resources with limited privileges. This combination directly addresses both authentication and authorization for external identities.
Why the other options are wrong
- A. Directory Service is for corporate directories, not social logins. Organizations is for account management, not user authorization.
- B. IAM is primarily for AWS users/roles, not for authenticating external social/corporate identities directly for applications.
- D. Cognito Identity Pools provide authorization to AWS resources, not authentication. Lambda can perform custom authorization, but Identity Pools simplify the federation aspect.
Cognito User Pools & Identity Pools
Amazon Cognito User Pools provide a secure user directory for sign-up and sign-in. Amazon Cognito Identity Pools (Federated Identities) enable you to grant authenticated users (from User Pools or other providers) temporary, limited-privilege access to AWS resources.
- User Pools: Authentication, user directory, integrates with social/corporate IDPs.
- Identity Pools: Authorization, federates authenticated users to AWS, grants temporary AWS credentials.
- Often used together for full auth/authz solution for external users.
Memory trick: User Pool finds the user, Identity Pool gives them the AWS key.