AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesEasy

A company is migrating its on-premises LDAP directory to AWS and needs a managed directory service that can integrate with existing Windows applications and provide single sign-on (SSO) capabilities. Which AWS directory service should they choose?

  1. AAWS Managed Microsoft AD
  2. BSimple AD
  3. CAmazon Cognito User Pools
  4. DAWS Directory Service for Microsoft Active Directory (AD Connector)
Show answer & explanation

Correct answer: A. AWS Managed Microsoft AD

AWS Managed Microsoft AD provides a fully managed, highly available Microsoft Active Directory that is compatible with existing Windows applications and supports single sign-on, making it the best choice for migrating from on-premises LDAP with Windows application integration needs.

Why the other options are wrong

  • B. Simple AD is a Samba-based directory service, compatible with Active Directory but lacks full AD features like trusts and advanced group policies, making it less suitable for complex Windows application integration.
  • C. Amazon Cognito User Pools is a managed user directory for web and mobile applications, not a Microsoft Active Directory compatible service for traditional Windows applications.
  • D. AD Connector is a proxy that connects to an *on-premises* Active Directory. The requirement is to *migrate* to AWS, not just connect to an existing on-premises one.

AWS Managed Microsoft AD

A fully managed, highly available Microsoft Active Directory service in the AWS Cloud, offering full compatibility with Windows applications and SSO.

  • Fully managed Microsoft AD.
  • Compatible with Windows applications.
  • Supports single sign-on (SSO).
  • Can establish trusts with on-premises AD.

Memory trick: AD: All Directories Done

More Design Secure Architectures questions