AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesEasy
A company is migrating its on-premises LDAP directory to AWS and needs a managed directory service that can integrate with existing Windows applications and provide single sign-on (SSO) capabilities. Which AWS directory service should they choose?
- AAWS Managed Microsoft AD
- BSimple AD
- CAmazon Cognito User Pools
- DAWS Directory Service for Microsoft Active Directory (AD Connector)
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Managed Microsoft AD
AWS Managed Microsoft AD provides a fully managed, highly available Microsoft Active Directory that is compatible with existing Windows applications and supports single sign-on, making it the best choice for migrating from on-premises LDAP with Windows application integration needs.
Why the other options are wrong
- B. Simple AD is a Samba-based directory service, compatible with Active Directory but lacks full AD features like trusts and advanced group policies, making it less suitable for complex Windows application integration.
- C. Amazon Cognito User Pools is a managed user directory for web and mobile applications, not a Microsoft Active Directory compatible service for traditional Windows applications.
- D. AD Connector is a proxy that connects to an *on-premises* Active Directory. The requirement is to *migrate* to AWS, not just connect to an existing on-premises one.
AWS Managed Microsoft AD
A fully managed, highly available Microsoft Active Directory service in the AWS Cloud, offering full compatibility with Windows applications and SSO.
- Fully managed Microsoft AD.
- Compatible with Windows applications.
- Supports single sign-on (SSO).
- Can establish trusts with on-premises AD.
Memory trick: AD: All Directories Done