AWS Certified Solutions Architect – ProfessionalDesign Solutions for Organizational ComplexityHard

A large enterprise with a global presence is planning to migrate several on-premises applications to AWS. These applications have strict data residency requirements, requiring data to remain within specific geographic boundaries. The enterprise also uses a centralized identity provider (IdP) for all its on-premises users and wants to maintain a single sign-on (SSO) experience for applications migrated to AWS. The solution must minimize operational overhead and ensure compliance with regulatory standards. Which combination of AWS services and strategies should a solutions architect recommend to meet these requirements?

  1. AUse AWS Organizations to create separate accounts for each region, AWS Directory Service for Microsoft Active Directory for identity synchronization, and AWS Global Accelerator for application access.
  2. BDeploy applications in a single AWS Region and use AWS WAF to enforce geo-blocking rules, synchronize identities using AWS Identity and Access Management (IAM) roles, and leverage AWS Transit Gateway for network connectivity.
  3. CUtilize AWS Control Tower to establish a multi-account strategy with specific organizational units (OUs) for each geographic region, integrate AWS IAM Identity Center with the on-premises IdP, and deploy applications in AWS Regions that comply with data residency.
  4. DImplement AWS PrivateLink for secure connectivity between on-premises and AWS, manage identities with AWS Cognito User Pools, and distribute applications using Amazon CloudFront with geo-restriction.
Show answer & explanation

Correct answer: C. Utilize AWS Control Tower to establish a multi-account strategy with specific organizational units (OUs) for each geographic region, integrate AWS IAM Identity Center with the on-premises IdP, and deploy applications in AWS Regions that comply with data residency.

AWS Control Tower provides a multi-account environment with OUs, which is ideal for managing data residency across regions. IAM Identity Center integrates with on-premises IdPs for SSO, and deploying applications in specific AWS Regions ensures data residency compliance. This combination effectively addresses all requirements.

Why the other options are wrong

  • A. AWS Organizations helps with account structure but doesn't inherently manage data residency or provide a comprehensive setup like Control Tower. AWS Directory Service is for Active Directory, not a general IdP integration for SSO, and Global Accelerator is for performance, not data residency.
  • B. Deploying in a single region does not meet data residency requirements if data needs to be in multiple specific regions. AWS WAF geo-blocking restricts access, not data storage location. IAM roles are for authorization within AWS, not for integrating an external IdP for SSO.
  • D. AWS PrivateLink is for secure private connectivity, not identity or data residency. AWS Cognito is a managed identity service, but IAM Identity Center is designed for enterprise SSO integration with existing IdPs. CloudFront with geo-restriction controls content delivery, not data residency for the underlying application data.

AWS Control Tower

A service that sets up and governs a secure, multi-account AWS environment, enforcing best practices and compliance.

  • Automates setting up a landing zone.
  • Provides guardrails for compliance.
  • Centralizes identity and access management.

Memory trick: Control your Tower, Identity your Center, Region your Data.

More Design Solutions for Organizational Complexity questions