A large enterprise with a global presence is planning to migrate several on-premises applications to AWS. These applications have strict data residency requirements, requiring data to remain within specific geographic boundaries. The enterprise also uses a centralized identity provider (IdP) for all its on-premises users and wants to maintain a single sign-on (SSO) experience for applications migrated to AWS. The solution must minimize operational overhead and ensure compliance with regulatory standards. Which combination of AWS services and strategies should a solutions architect recommend to meet these requirements?
- AUse AWS Organizations to create separate accounts for each region, AWS Directory Service for Microsoft Active Directory for identity synchronization, and AWS Global Accelerator for application access.
- BDeploy applications in a single AWS Region and use AWS WAF to enforce geo-blocking rules, synchronize identities using AWS Identity and Access Management (IAM) roles, and leverage AWS Transit Gateway for network connectivity.
- CUtilize AWS Control Tower to establish a multi-account strategy with specific organizational units (OUs) for each geographic region, integrate AWS IAM Identity Center with the on-premises IdP, and deploy applications in AWS Regions that comply with data residency.
- DImplement AWS PrivateLink for secure connectivity between on-premises and AWS, manage identities with AWS Cognito User Pools, and distribute applications using Amazon CloudFront with geo-restriction.
Show answer & explanationAnswer & explanation
Correct answer: C. Utilize AWS Control Tower to establish a multi-account strategy with specific organizational units (OUs) for each geographic region, integrate AWS IAM Identity Center with the on-premises IdP, and deploy applications in AWS Regions that comply with data residency.
AWS Control Tower provides a multi-account environment with OUs, which is ideal for managing data residency across regions. IAM Identity Center integrates with on-premises IdPs for SSO, and deploying applications in specific AWS Regions ensures data residency compliance. This combination effectively addresses all requirements.
Why the other options are wrong
- A. AWS Organizations helps with account structure but doesn't inherently manage data residency or provide a comprehensive setup like Control Tower. AWS Directory Service is for Active Directory, not a general IdP integration for SSO, and Global Accelerator is for performance, not data residency.
- B. Deploying in a single region does not meet data residency requirements if data needs to be in multiple specific regions. AWS WAF geo-blocking restricts access, not data storage location. IAM roles are for authorization within AWS, not for integrating an external IdP for SSO.
- D. AWS PrivateLink is for secure private connectivity, not identity or data residency. AWS Cognito is a managed identity service, but IAM Identity Center is designed for enterprise SSO integration with existing IdPs. CloudFront with geo-restriction controls content delivery, not data residency for the underlying application data.
AWS Control Tower
A service that sets up and governs a secure, multi-account AWS environment, enforcing best practices and compliance.
- Automates setting up a landing zone.
- Provides guardrails for compliance.
- Centralizes identity and access management.
Memory trick: Control your Tower, Identity your Center, Region your Data.