Which AWS Service Enables Single Sign-On Across Multiple AWS Accounts?

Identify AWS access management capabilities.
Answer Correct answer: C — AWS IAM Identity Center (AWS Single Sign-On) provides one set of credentials for centralized authentication and authorization across multiple AWS accounts.

A company wants to allow users to authenticate and authorize multiple AWS accounts by using a single set of credentials. Which AWS service or resource will meet this requirement?

  1. AWS Organizations
  2. IAM user
  3. AWS IAM Identity Center (AWS Single Sign-On) Correct Answer
  4. AWS Control Tower

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the difference between multi-account governance services (AWS Organizations, Control Tower) and the identity service that actually authenticates people (IAM Identity Center); the trap is picking Organizations because it also spans multiple accounts.

AWS IAM Identity Center (AWS Single Sign-On) is the service that lets users authenticate once and be authorized across many AWS accounts with one set of credentials. This page confirms why option C is the answer and why IAM users, AWS Organizations, and AWS Control Tower do not provide that sign-in capability.

Selecting AWS Organizations, since it manages and consolidates multiple accounts, but Organizations only governs accounts and billing — it stores no user identities and issues no credentials, so it cannot authenticate users.

Community Discussion (3 comments)

[Removed] 👍 1 Selected: C
Manage access to a multi-account AWS environment Your users can use their directory credentials for single sign-on access to multiple AWS accounts. Their personalized web user portal shows their assigned roles in AWS accounts in one place. Users can sign in through the AWS Command Line Interface, AWS SDKs, or AWS Console Mobile Application using their directory credentials for a consistent authentication experience. https://aws.amazon.com/iam/identity-center/
bindu991 👍 2 Selected: C
AWS SSO
Aghajee 👍 3
C. AWS IAM Identity Center (AWS Single Sign-On) AWS Single Sign-On (SSO) enables centralized authentication and authorization across multiple AWS accounts and other business applications. It allows users to sign in once and access resources in various accounts without the need for separate credentials for each account. This helps simplify access management in a multi-account environment.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS IAM Identity Center (formerly AWS Single Sign-On) is the AWS service purpose-built for workforce identity: it holds or connects to a directory, and users sign in once and then assume permission sets (roles) in any number of AWS accounts. The requirement in this question — "authenticate and authorize multiple AWS accounts by using a single set of credentials" — maps exactly to that single sign-on portal, often reached via the AWS access portal or AWS CLI. Because permission sets are defined centrally and assigned per account, the user never needs separate credentials for each account. That is why option C is the answer the ACLF-C02 blueprint expects under access management capabilities.

Why the Other Options Are Wrong

Option A, AWS Organizations, is an account-management and consolidated-billing container: it creates and groups accounts and applies service control policies, but it has no user credential store or sign-in experience. Option B, an IAM user, is scoped to one account only — a single IAM user cannot natively authenticate into other accounts, which is precisely the problem the company is trying to solve. Option D, AWS Control Tower, automates landing-zone setup and governance across accounts, but it orchestrates accounts rather than authenticating end users. Note that IAM Identity Center is typically enabled within an organization from Organizations, which is why options A and D can feel adjacent to the requirement.

Community Comment Notes

Learners converged on C, and Aghajee's explanation correctly frames the service as providing "centralized authentication and authorization across multiple AWS accounts" plus one sign-in instead of per-account credentials. Another commenter highlights that "users can use their directory credentials for single sign-on access to multiple AWS accounts" and that the access portal shows assigned roles in one place, which matches the portal behavior you should picture on the exam. bindu991 simply wrote "AWS SSO", the older name of the same service — useful because the exam may still use either name. There is no community dissent here, and the unanimous reasoning aligns with the official AWS documentation.

Official Reference

Exam Strategy

When a question mentions one identity or one credential set spanning many AWS accounts, immediately shortlist IAM Identity Center and treat AWS Organizations as the governance layer it sits inside rather than the authentication answer. Also remember the service's dual naming as AWS IAM Identity Center and AWS Single Sign-On, since both appear in exam wording.

Frequently Asked Questions

Why is AWS Organizations not the answer for single sign-on across accounts?

AWS Organizations creates, groups, and governs accounts and consolidated billing, but it stores no user identities and has no sign-in portal. It hosts IAM Identity Center, yet it cannot authenticate users itself.

Can one IAM user authenticate into several AWS accounts directly?

No. An IAM user exists in a single account; cross-account access requires assuming a role, which is why a centralized identity service such as IAM Identity Center is needed for one credential set.

More CLF-C02 FAQ →

Related Analysis

Practice All CLF-C02 Questions

Access 120 questions with complete answers and detailed explanations.

View Full CLF-C02 Practice Test →

← Back to CLF-C02 Study Guide