Which AWS Service Enables Single Sign-On Across Multiple AWS Accounts?
A company wants to allow users to authenticate and authorize multiple AWS accounts by using a single set of credentials. Which AWS service or resource will meet this requirement?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the difference between multi-account governance services (AWS Organizations, Control Tower) and the identity service that actually authenticates people (IAM Identity Center); the trap is picking Organizations because it also spans multiple accounts.
AWS IAM Identity Center (AWS Single Sign-On) is the service that lets users authenticate once and be authorized across many AWS accounts with one set of credentials. This page confirms why option C is the answer and why IAM users, AWS Organizations, and AWS Control Tower do not provide that sign-in capability.
Selecting AWS Organizations, since it manages and consolidates multiple accounts, but Organizations only governs accounts and billing — it stores no user identities and issues no credentials, so it cannot authenticate users.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS IAM Identity Center (formerly AWS Single Sign-On) is the AWS service purpose-built for workforce identity: it holds or connects to a directory, and users sign in once and then assume permission sets (roles) in any number of AWS accounts. The requirement in this question — "authenticate and authorize multiple AWS accounts by using a single set of credentials" — maps exactly to that single sign-on portal, often reached via the AWS access portal or AWS CLI. Because permission sets are defined centrally and assigned per account, the user never needs separate credentials for each account. That is why option C is the answer the ACLF-C02 blueprint expects under access management capabilities.Why the Other Options Are Wrong
Option A, AWS Organizations, is an account-management and consolidated-billing container: it creates and groups accounts and applies service control policies, but it has no user credential store or sign-in experience. Option B, an IAM user, is scoped to one account only — a single IAM user cannot natively authenticate into other accounts, which is precisely the problem the company is trying to solve. Option D, AWS Control Tower, automates landing-zone setup and governance across accounts, but it orchestrates accounts rather than authenticating end users. Note that IAM Identity Center is typically enabled within an organization from Organizations, which is why options A and D can feel adjacent to the requirement.Community Comment Notes
Learners converged on C, and Aghajee's explanation correctly frames the service as providing "centralized authentication and authorization across multiple AWS accounts" plus one sign-in instead of per-account credentials. Another commenter highlights that "users can use their directory credentials for single sign-on access to multiple AWS accounts" and that the access portal shows assigned roles in one place, which matches the portal behavior you should picture on the exam. bindu991 simply wrote "AWS SSO", the older name of the same service — useful because the exam may still use either name. There is no community dissent here, and the unanimous reasoning aligns with the official AWS documentation.Official Reference
Exam Strategy
When a question mentions one identity or one credential set spanning many AWS accounts, immediately shortlist IAM Identity Center and treat AWS Organizations as the governance layer it sits inside rather than the authentication answer. Also remember the service's dual naming as AWS IAM Identity Center and AWS Single Sign-On, since both appear in exam wording.
Frequently Asked Questions
Why is AWS Organizations not the answer for single sign-on across accounts?
AWS Organizations creates, groups, and governs accounts and consolidated billing, but it stores no user identities and has no sign-in portal. It hosts IAM Identity Center, yet it cannot authenticate users itself.
Can one IAM user authenticate into several AWS accounts directly?
No. An IAM user exists in a single account; cross-account access requires assuming a role, which is why a centralized identity service such as IAM Identity Center is needed for one credential set.
Related Analysis
Practice All CLF-C02 Questions
Access 120 questions with complete answers and detailed explanations.
View Full CLF-C02 Practice Test →