Which AWS service federates a third-party IdP for employee AWS access?
A company uses a third-party identity provider (IdP). The company wants to provide its employees with access to AWS accounts and services without requiring another set of login credentials. Which AWS service will meet this requirement?
Community Votes
81% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you can separate workforce federation (IAM Identity Center) from customer-facing application identity (Cognito); the trap is picking Cognito because it also speaks SAML 2.0 and OIDC.
When employees must reach AWS accounts and services with their existing third-party IdP credentials, AWS IAM Identity Center (the successor to AWS SSO) is the service that provides that workforce federation. This page confirms answer C and explains why Amazon Cognito, AWS Directory Service, and AWS RAM do not satisfy the 'no second set of credentials' requirement.
Choosing Amazon Cognito because it integrates with external IdPs via OIDC/SAML — but Cognito is a customer identity service for web and mobile app users, and it would still create its own user pool identities rather than signing employees directly into AWS accounts.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS IAM Identity Center is the workforce identity service that federates an external identity provider — Okta, Microsoft Entra ID, or any SAML 2.0/OIDC-compliant IdP — so employees sign in once and then reach assigned AWS accounts and business applications. The question's decisive phrase is that employees should get access "without requiring another set of login credentials," which is exactly the single sign-on behavior Identity Center delivers through permission sets and account assignments. It replaced AWS Single Sign-On, and the AWS prescriptive guidance lists supported external identity sources for this purpose. Because the target resources are AWS accounts and services used by the company's own employees, this is workforce access management, not application user management.
Why the Other Options Are Wrong
Amazon Cognito is a customer identity and access management service: it adds sign-up and sign-in to your own web and mobile applications and issues its own tokens from a user pool, so it addresses app end users rather than employees needing direct AWS console and service access. AWS Directory Service hosts or connects Active Directory and LDAP directories, and while it can act as an identity source behind a federation service, it is not the SSO front end that grants employees AWS account access. AWS Resource Access Manager shares resources such as subnets and transit gateways across accounts; it has nothing to do with identity federation or login credentials.
Community Comment Notes
efromdc states the giveaway cleanly: the "key is '...WITHOUT requiring another set of login credentials'," which rules out Cognito because a Cognito user pool would be a different set of credentials. geocis admits "I initially answered option (B), Amazon Cognito, but I read too fast," a good reminder that Cognito looks plausible until you notice the word employees. ShaiTay summarizes Identity Center as providing "federated access, single sign on, and centralized management," and SFAY points at the AWS prerequisite identity-sources documentation. A few learners (Zerro, RockyRoccoco) argued for B or A, but neither reasoning addresses workforce sign-in to AWS accounts, and the vote record of 76 for C reflects the correct reading.
Exam Strategy Tip
Scan for the actor first: "employees," "workforce," "corporate credentials," and "AWS accounts" mean IAM Identity Center, while "customers," "app users," and "web/mobile sign-in" mean Cognito.
Official Reference
Exam Strategy
Identify the audience before the protocol: if the people signing in are employees consuming AWS accounts and services, the answer is AWS IAM Identity Center; if they are end users of your application, it is Amazon Cognito. The phrase "without another set of login credentials" is the strongest signal for federated workforce SSO.
Frequently Asked Questions
Why is Amazon Cognito not the answer for employee access to AWS accounts?
Cognito is a customer identity service for web and mobile applications; it authenticates your app's end users with its own user pool credentials rather than signing employees into AWS accounts.
Can AWS IAM Identity Center use a third-party IdP like Okta as an identity source?
Yes. Identity Center supports external SAML 2.0 and OIDC identity providers as identity sources, which is why employees keep their existing corporate credentials.
Related Analysis
Practice All CLF-C02 Questions
Access 120 questions with complete answers and detailed explanations.
View Full CLF-C02 Practice Test →