A company manages multiple AWS accounts using AWS Organizations. The company wants employees to sign in using their existing corporate credentials from an on-premises Microsoft Active Directory. The company also needs a single sign-on (SSO) experience so that each employee can access the AWS Management Console for any authorized account without needing separate passwords. Additionally, the company wants to centrally manage permissions across all accounts. Which AWS service should the company use to meet these requirements?
AWS IAM Identity Center is the service that centrally manages single sign-on access to multiple AWS accounts and applications. It integrates with Microsoft Active Directory and allows employees to use their existing corporate credentials to access the AWS Management Console across all authorized accounts with a single sign-on experience, and it centralizes permission management.
Why this answer
AWS IAM Identity Center (formerly AWS SSO) is the correct service because it provides a centralized place to manage single sign-on (SSO) access to multiple AWS accounts and applications. It integrates with an on-premises Microsoft Active Directory via the AWS Directory Service or an external identity provider, allowing employees to use their existing corporate credentials. IAM Identity Center also enables you to centrally define and manage permissions across all accounts in AWS Organizations, meeting all stated requirements.
Exam trap
The trap here is that candidates often confuse AWS Directory Service with a complete SSO solution, but Directory Service only provides the directory infrastructure, not the centralized permission management or SSO portal that IAM Identity Center delivers.
Why the other options are wrong
IAM does not provide SSO with corporate credentials or centralized permission management across multiple AWS accounts; it is designed for user and permission management within a single account.
AWS Directory Service provides managed Microsoft Active Directory but does not offer single sign-on (SSO) to the AWS Management Console or centralized permission management across multiple accounts; it only integrates with IAM for directory-based authentication.
Amazon Cognito is designed for customer identity and access management (CIAM) for web and mobile apps, not for workforce SSO with corporate Active Directory. It does not integrate with AWS Organizations to centrally manage permissions across multiple AWS accounts.
When would these options actually be correct?
A company needs to create individual IAM users with long-term credentials for direct AWS API access, and does not require federation with an external identity provider or SSO across multiple accounts.
A company needs to extend its on-premises Active Directory to AWS for EC2 instances to join the domain, or to enable LDAP-based authentication for applications, without requiring SSO or multi-account permission management.
A company builds a mobile app and wants to allow users to sign in with their social media accounts (e.g., Facebook, Google) or through a custom identity provider. Amazon Cognito user pools would be the correct service to handle authentication and provide temporary AWS credentials for accessing backend resources.
Why candidates pick the wrong answer
Candidates may think IAM is the default AWS identity service and assume it can handle SSO and multi-account permissions, overlooking that IAM Identity Center is specifically built for these use cases.
Candidates see 'Microsoft Active Directory' and assume Directory Service is the solution, overlooking that the question specifically requires SSO and centralized permissions across accounts, which are provided by IAM Identity Center.
Candidates may confuse Amazon Cognito's ability to federate with external identity providers (like Active Directory) with the workforce SSO scenario, not realizing that Cognito is primarily for customer-facing apps, not for managing employee access to AWS accounts.