Which AWS service federates a third-party IdP for employee AWS access?

Identify AWS access management capabilities. Understand AWS Cloud security, governance, and compliance concepts.
Answer Correct answer: C — AWS IAM Identity Center federates the third-party IdP so employees sign in with existing credentials and get access to AWS accounts and services.

A company uses a third-party identity provider (IdP). The company wants to provide its employees with access to AWS accounts and services without requiring another set of login credentials. Which AWS service will meet this requirement?

  1. AWS Directory Service
  2. Amazon Cognito
  3. AWS IAM Identity Center Correct Answer
  4. AWS Resource Access Manager (AWS RAM)

Community Votes

C
81%
B
19%

81% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you can separate workforce federation (IAM Identity Center) from customer-facing application identity (Cognito); the trap is picking Cognito because it also speaks SAML 2.0 and OIDC.

When employees must reach AWS accounts and services with their existing third-party IdP credentials, AWS IAM Identity Center (the successor to AWS SSO) is the service that provides that workforce federation. This page confirms answer C and explains why Amazon Cognito, AWS Directory Service, and AWS RAM do not satisfy the 'no second set of credentials' requirement.

Choosing Amazon Cognito because it integrates with external IdPs via OIDC/SAML — but Cognito is a customer identity service for web and mobile app users, and it would still create its own user pool identities rather than signing employees directly into AWS accounts.

Community Discussion (8 comments)

jj112233 👍 9
B. Amazon Cognito Amazon Cognito allows you to add user sign-up, sign-in, and access control to your web and mobile apps quickly and easily. With Cognito, you can integrate with your existing third-party identity provider (IdP) through industry-standard protocols such as OpenID Connect (OIDC) and SAML 2.0.
ShaiTay 👍 3 Selected: C
C. AWS IAM Identity Center - provides federated access, single sign on, and centralized management
Meow7 👍 1
The key is "...WITHOUT requiring another set of login credentials." please help with discussion on 478~480. Thanks.
RockyRoccoco 👍 1 Selected: A
AWS Directory Service: AWS Directory Service allows you to integrate AWS with your existing Active Directory or other LDAP-based directory services. You can use AWS Directory Service with AWS Single Sign-On (SSO) to enable federated access to AWS accounts and services. This means employees can use their existing corporate credentials (from the third-party IdP) to sign in to AWS without needing separate AWS-specific credentials.
efromdc 👍 3 Selected: C
The key is "...WITHOUT requiring another set of login credentials." Therefore the answer is C, IAM. B, Cognito, would be using an a different / additional set of login credentials.
geocis 👍 4 Selected: C
I initially answered option (B), Amazon Cognito, but I read too fast. The company uses a third-party IDP and wants to provide its employees access to AWS accounts and services without creating new logins. This can be accomplished by using IAM. AWS IAM Identity Center replaced AWS SSO (Single Sign-on). This service provides a single place to create and manage multiple AWS accounts and business applications. It also creates or connects workforce identities and manages their access centrally. SSO access to AWS accounts and SSO Access to Applications such as M365, Salesforce, and custom SAML 2.0 applications.
SFAY 👍 3 Selected: C
Definitely C. https://docs.aws.amazon.com/singlesignon/latest/userguide/prereq-identity-sources.html
Zerro 👍 3 Selected: B
Correct Answer is B. Awful, just awful, all given answers are wrong.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS IAM Identity Center is the workforce identity service that federates an external identity provider — Okta, Microsoft Entra ID, or any SAML 2.0/OIDC-compliant IdP — so employees sign in once and then reach assigned AWS accounts and business applications. The question's decisive phrase is that employees should get access "without requiring another set of login credentials," which is exactly the single sign-on behavior Identity Center delivers through permission sets and account assignments. It replaced AWS Single Sign-On, and the AWS prescriptive guidance lists supported external identity sources for this purpose. Because the target resources are AWS accounts and services used by the company's own employees, this is workforce access management, not application user management.

Why the Other Options Are Wrong

Amazon Cognito is a customer identity and access management service: it adds sign-up and sign-in to your own web and mobile applications and issues its own tokens from a user pool, so it addresses app end users rather than employees needing direct AWS console and service access. AWS Directory Service hosts or connects Active Directory and LDAP directories, and while it can act as an identity source behind a federation service, it is not the SSO front end that grants employees AWS account access. AWS Resource Access Manager shares resources such as subnets and transit gateways across accounts; it has nothing to do with identity federation or login credentials.

Community Comment Notes

efromdc states the giveaway cleanly: the "key is '...WITHOUT requiring another set of login credentials'," which rules out Cognito because a Cognito user pool would be a different set of credentials. geocis admits "I initially answered option (B), Amazon Cognito, but I read too fast," a good reminder that Cognito looks plausible until you notice the word employees. ShaiTay summarizes Identity Center as providing "federated access, single sign on, and centralized management," and SFAY points at the AWS prerequisite identity-sources documentation. A few learners (Zerro, RockyRoccoco) argued for B or A, but neither reasoning addresses workforce sign-in to AWS accounts, and the vote record of 76 for C reflects the correct reading.

Exam Strategy Tip

Scan for the actor first: "employees," "workforce," "corporate credentials," and "AWS accounts" mean IAM Identity Center, while "customers," "app users," and "web/mobile sign-in" mean Cognito.

Official Reference

Exam Strategy

Identify the audience before the protocol: if the people signing in are employees consuming AWS accounts and services, the answer is AWS IAM Identity Center; if they are end users of your application, it is Amazon Cognito. The phrase "without another set of login credentials" is the strongest signal for federated workforce SSO.

Frequently Asked Questions

Why is Amazon Cognito not the answer for employee access to AWS accounts?

Cognito is a customer identity service for web and mobile applications; it authenticates your app's end users with its own user pool credentials rather than signing employees into AWS accounts.

Can AWS IAM Identity Center use a third-party IdP like Okta as an identity source?

Yes. Identity Center supports external SAML 2.0 and OIDC identity providers as identity sources, which is why employees keep their existing corporate credentials.

More CLF-C02 FAQ →

Related Analysis

Practice All CLF-C02 Questions

Access 120 questions with complete answers and detailed explanations.

View Full CLF-C02 Practice Test →

← Back to CLF-C02 Study Guide