Federate the corporate IdP through IAM Identity Center with SAML and deny IAM user login profile creation via SCP
A company uses AWS Organizations to manage its AWS accounts. A DevOps engineer must ensure that all users who access the AWS Management Console are authenticated through the company’s corporate identity provider (IdP). Which combination of steps will meet these requirements? (Choose two.)
Community Votes
82% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
SAML 2.0 federation in IAM Identity Center establishes the corporate IdP as the authentication path for the console (B), while an SCP denying iam:CreateLoginProfile and iam:UpdateLoginProfile closes the alternate door of IAM user console logins, an explicit deny that cannot be overridden by any identity-based policy (E). Option C is invalid because permissions boundaries are an IAM Identity Center concept only in the sense of session permissions and cannot deny password logins for IAM users. Option A misuses GuardDuty, a threat detection service, for authentication enforcement.
Every console user must authenticate through the corporate identity provider. Configuring identity federation with SAML 2.0 in AWS IAM Identity Center makes the corporate IdP the authoritative source for console access. Because IAM Identity Center only governs access it brokers, an SCP denying the creation and update of login profiles prevents anyone from minting a password-based IAM user login, guaranteeing that console authentication can only occur through the federated IdP.
Using GuardDuty to deny IAM user logins (A)—GuardDuty is a threat detection service and has no capability to enforce or deny console authentication methods. Trying to create a permissions boundary in IAM Identity Center to deny password logins (C)—permissions boundaries cap the maximum permissions of a principal and do not apply to IAM users or their console login mechanisms. The enforcement point for blocking password-based IAM user logins is an organization-level SCP.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Configuring SAML 2.0 identity federation in AWS IAM Identity Center makes the corporate identity provider the federated source for console authentication, so users sign in through the IdP rather than with AWS-managed credentials (B). However, federation alone does not prevent someone from creating an IAM user with a console password and logging in directly, so an SCP that denies iam:CreateLoginProfile and iam:UpdateLoginProfile is attached to enforce the requirement at the organization level (E). An explicit SCP deny sits above all identity-based policies and cannot be overridden, so no principal in the organization can establish a password-based IAM user login, which makes corporate IdP authentication the only console path.Why the Other Options Are Wrong
A proposes using GuardDuty with a delegated administrator to deny IAM user logins. GuardDuty is a threat detection service that generates findings; it has no ability to deny an authentication method. C proposes creating a permissions boundary in IAM Identity Center to deny password logins for IAM users; a permissions boundary limits the maximum permissions of a principal and does not govern IAM user console credentials, so it cannot achieve this. D proposes creating IAM groups in the management account to apply consistent permissions, which manages authorization rather than authentication and does not force IdP logins. B and E are the correct combination.Community Comment Notes
Community voted B,E (82), with B,C an 18 percent minority. Commenters agreed that B establishes SAML federation with the corporate IdP and that E enforces the requirement by preventing creation of IAM user login profiles, with KaranNishad supplying the exact SCP statement denying iam:CreateLoginProfile and iam:UpdateLoginProfile.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →