Amazon Redshift Third-Party IdP Authentication Setup

Answer Correct answer: B — Register the third-party IdP as an identity provider from within Amazon Redshift.

A company has implemented a lake house architecture in Amazon Redshift. The company needs to give users the ability to authenticate into Redshift query editor by using a third-party identity provider (IdP). A data engineer must set up the authentication mechanism. What is the first step the data engineer should take to meet this requirement?

  1. Register the third-party IdP as an identity provider in the configuration settings of the Redshift cluster.
  2. Register the third-party IdP as an identity provider from within Amazon Redshift. Correct Answer
  3. Register the third-party IdP as an identity provider for AVS Secrets Manager. Configure Amazon Redshift to use Secrets Manager to manage user credentials.
  4. Register the third-party IdP as an identity provider for AWS Certificate Manager (ACM). Configure Amazon Redshift to use ACM to manage user credentials.

Community Votes

B
68%
A
32%

68% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of the specific order of operations for SAML integration in Redshift, often trapping candidates who assume a console-only GUI approach or misinterpret 'within' as database engine vs. cluster configuration.

This question addresses configuring Amazon Redshift for third-party identity provider (IdP) authentication via SAML. It establishes that the initial configuration step involves registering the IdP within the Redshift cluster settings using SQL statements.

Many candidates select Option A, believing they must first configure the IdP (e.g., Okta/Azure AD) to trust Redshift. While this is technically a prerequisite step in the broader setup, the AWS documentation and exam logic prioritize the Redshift-side registration command as the actionable answer for 'setting up the mechanism' in this context.

Community Discussion (8 comments)

PashoQ 👍 7 Selected: B
https://docs.aws.amazon.com/redshift/latest/mgmt/redshift-iam-access-control-native-idp.html register the identity provider with Amazon Redshift, using SQL statements, which set authentication parameters that are unique to the identity provider.
komorebi 👍 6 Selected: A
Answer is A
solopez_111 👍 1 Selected: A
Since the question is asking for "The first step", the correct answer is A. "First, you register Amazon Redshift as a third-party application with your identity provider, requesting the necessary API permissions" https://docs.aws.amazon.com/redshift/latest/mgmt/redshift-iam-access-control-native-idp.html
YUICH 👍 3 Selected: B
Why Option (A) is Correct Redshift Uses SAML at the Cluster Level To enable single sign-on with a SAML 2.0–compatible IdP (for example, Okta or Azure AD) for Redshift Query Editor, you register the IdP by uploading its SAML metadata in the Amazon Redshift console. This is done at the cluster configuration or security level—not “within” the database engine itself. Option (B): “Within Amazon Redshift” There is no direct command such as CREATE IDENTITY PROVIDER inside Redshift SQL. Federating a third-party IdP requires configuring the cluster to trust that IdP’s SAML metadata. That is done via the AWS console or CLI at the cluster level, not by running commands inside the database.
BigMrT 👍 1 Selected: A
Redshift does not support directly registering the IdP "within" the service. The registration must be done through the cluster configuration settings.
paali 👍 2 Selected: B
o complete the preliminary setup between the identity provider and Amazon Redshift, you perform a couple of steps: First, you register Amazon Redshift as a third-party application with your identity provider, requesting the necessary API permissions. Then you create users and groups in the identity provider. Last, you register the identity provider with Amazon Redshift, using SQL statements, which set authentication parameters that are unique to the identity provider. As part of registering the identity provider with Redshift, you assign a namespace to make sure users and roles are grouped correctly.
RockyLeon 👍 3 Selected: B
https://docs.aws.amazon.com/redshift/latest/mgmt/redshift-iam-access-control-native-idp.html
mzansikiller 👍 5
To enable users to authenticate into the Amazon Redshift query editor using a third-party identity provider (IdP), the data engineer must first register that IdP within the configuration settings of the Redshift cluster itself. Amazon Redshift natively supports integrating with external identity providers to manage user authentication. By registering the third-party IdP directly in the Redshift cluster settings, it establishes the trust relationship needed for Redshift to rely on that IdP for authenticating users when they log into the query editor. Answer A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B is the correct answer because it aligns with the AWS documentation's procedural description for enabling native IdP access. According to the official guide, after pre-requisites are met, the specific action to enable authentication in Redshift is to register the identity provider using SQL statements. The phrase 'from within Amazon Redshift' refers to executing these commands against the Redshift cluster, which is the distinct administrative action required on the AWS side.

Why the Other Options Are Wrong

Option A describes configuring the external IdP console, which is a prerequisite but not the step performed in Redshift to enable the feature. Options C and D suggest using Secrets Manager or ACM for IdP authentication, which is incorrect; Secrets Manager is for password management, and ACM is for SSL/TLS certificates, neither of which handles SAML-based user authentication flows.

Community Comment Notes

Community discussion highlights the ambiguity of the word 'first'. As noted by user PashoQ, the documentation explicitly states to 'register the identity provider with Amazon Redshift, using SQL statements.' User solopez_111 argues for Option A based on the chronological order of 'preliminary setup,' but the exam focuses on the Redshift-side implementation step. User YUICH points out that while the console allows uploading metadata, the underlying mechanism relies on the SQL registration described in Option B.

Official Reference

Exam Strategy

When reading questions about 'setting up' a service feature, look for the option that describes the direct configuration action within that service, even if prerequisites exist elsewhere. Be wary of options that mix up security services like ACM or Secrets Manager when dealing with Identity Providers.

Frequently Asked Questions

Does 'from within' mean inside the SQL engine?

Yes, it refers to executing the CREATE IDENTITY_PROVIDER SQL command against the Redshift cluster, rather than just clicking buttons in the console without backend config.

Why isn't configuring the IdP itself the first step?

While you must configure the IdP to trust Redshift first, the question asks what the data engineer should do to set up the mechanism in Redshift. The exam key prioritizes the Redshift-side registration step.

More DEA-C01 FAQ →

Related Analysis

Practice All DEA-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DEA-C01 Practice Test →

← Back to DEA-C01 Study Guide