AWS IAM Identity Center for Centralized Workforce Access
A company wants to manage sign-in security for workforce users. The company needs to create workforce users and centrally manage their access across all the company's AWS accounts and applications. Which AWS service will meet these requirements?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the distinction between identity services: IAM Identity Center is for internal workforce management, while Amazon Cognito is primarily for customer-facing application authentication.
AWS IAM Identity Center (formerly AWS SSO) is the service designed for centrally managing workforce user access across multiple AWS accounts and applications, distinguishing it from Amazon Cognito which targets external app users.
Users often select Amazon Cognito because it handles sign-ins, but fail to recognize that 'workforce users' implies an enterprise directory context where IAM Identity Center is the correct centralized solution.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS IAM Identity Center (AWS Single Sign-On) is specifically designed to manage access to AWS accounts and business applications centrally. It allows you to create workforce users in its integrated directory or sync with your existing identity provider (like Active Directory), providing a single portal for users to access all their assigned resources. This directly meets the requirement of creating and centrally managing workforce user access across all AWS accounts.Why the Other Options Are Wrong
Amazon Cognito (Option B) is optimized for adding sign-up and sign-in functionality to web and mobile apps, typically targeting external customers rather than internal workforce employees. While it can handle authentication, it does not provide the same level of centralized multi-account access management for enterprise workforces as IAM Identity Center. AWS Security Hub (Option C) is a security posture management service that aggregates findings, not an identity service. AWS Audit Manager (Option A) helps automate audits and compliance checks, unrelated to user access management.Community Comment Notes
Community consensus strongly supports D. One commenter noted that "IAM Identity Center = Centralized access management for AWS and Apps" contrasting it with Cognito's role. Another highlighted that Cognito is "more for third-part applications like credentials," reinforcing the workforce vs. customer distinction. Some users questioned if Cognito could be correct, but the specific mention of 'workforce users' and 'centrally manage... across all accounts' points definitively to IAM Identity Center.Exam Strategy
When you see 'workforce', 'employees', or 'centralized access across AWS accounts', immediately think IAM Identity Center. Reserve Cognito for scenarios involving 'web/mobile apps', 'external users', or 'customer identities'.
Frequently Asked Questions
Why isn't Amazon Cognito the right answer?
Cognito is designed for external customer apps, whereas IAM Identity Center is built for internal workforce management and multi-account access.
What does 'workforce users' imply here?
It refers to internal employees who need access to corporate AWS accounts, requiring an enterprise-grade identity solution like IAM Identity Center.
Related Analysis
Practice All CLF-C02 Questions
Access 120 questions with complete answers and detailed explanations.
View Full CLF-C02 Practice Test →