Federate the corporate IdP through IAM Identity Center with SAML and deny IAM user login profile creation via SCP

Answer Correct answer: B, E — federate the corporate IdP with SAML 2.0 in IAM Identity Center and deny IAM user login profile creation with an SCP.

A company uses AWS Organizations to manage its AWS accounts. A DevOps engineer must ensure that all users who access the AWS Management Console are authenticated through the company’s corporate identity provider (IdP). Which combination of steps will meet these requirements? (Choose two.)

  1. Use Amazon GuardDuty with a delegated administrator account Use GuardDuty to enforce denial of IAM user logins.
  2. Use AWS IAM Identity Center to configure identity federation with SAML 2.0. Correct Answer
  3. Create a permissions boundary in AWS IAM Identity Center to deny password logins for IAM users.
  4. Create IAM groups in the Organizations management account to apply consistent permissions for all IAM users.
  5. Create an SCP in Organizations to deny password creation for IAM users. Correct Answer

Community Votes

BE
82%
BC
18%

82% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

SAML 2.0 federation in IAM Identity Center establishes the corporate IdP as the authentication path for the console (B), while an SCP denying iam:CreateLoginProfile and iam:UpdateLoginProfile closes the alternate door of IAM user console logins, an explicit deny that cannot be overridden by any identity-based policy (E). Option C is invalid because permissions boundaries are an IAM Identity Center concept only in the sense of session permissions and cannot deny password logins for IAM users. Option A misuses GuardDuty, a threat detection service, for authentication enforcement.

Every console user must authenticate through the corporate identity provider. Configuring identity federation with SAML 2.0 in AWS IAM Identity Center makes the corporate IdP the authoritative source for console access. Because IAM Identity Center only governs access it brokers, an SCP denying the creation and update of login profiles prevents anyone from minting a password-based IAM user login, guaranteeing that console authentication can only occur through the federated IdP.

Using GuardDuty to deny IAM user logins (A)—GuardDuty is a threat detection service and has no capability to enforce or deny console authentication methods. Trying to create a permissions boundary in IAM Identity Center to deny password logins (C)—permissions boundaries cap the maximum permissions of a principal and do not apply to IAM users or their console login mechanisms. The enforcement point for blocking password-based IAM user logins is an organization-level SCP.

Community Discussion (5 comments)

limelight04 👍 2 Selected: BC
Use AWS IAM Identity Center to configure identity federation with SAML 2.0: Configure SAML-based federation between your corporate IdP and AWS IAM. This allows users to authenticate via your corporate identity provider when accessing the AWS Management Console. Create a permissions boundary in AWS IAM Identity Center: Set up a permissions boundary to deny password logins for IAM users. This ensures that users must authenticate through the corporate IdP rather than using IAM user credentials.
jamesf 👍 2 Selected: BE
Option B: Configure identity federation with SAML 2.0 using AWS IAM Identity Center. Option E: Implement an SCP to deny password creation for IAM users, enforcing IdP authentication. Incorrect for C - Permissions Boundaries - Permissions boundaries in AWS IAM Identity Center define the maximum permissions an IAM entity can have but are not used to control login methods or deny password logins. - Permissions boundaries do not restrict authentication methods or enforce federation. - Permissions boundaries are not applicable for denying IAM user logins.
tgv 👍 2
---> BE
trungtd 👍 3 Selected: BE
of course B. E enforce that users cannot log in directly with IAM credentials. Instead, they must use the SSO setup provided by AWS IAM Identity Center, ensuring compliance with the requirement to authenticate through the corporate IdP.
KaranNishad 👍 4 Selected: BE
BE is answer { "Version": "2012-10-17", "Statement": [ { "Effect": "Deny", "Action": [ "iam:CreateLoginProfile", "iam:UpdateLoginProfile" ], "Resource": "*" } ] }

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Configuring SAML 2.0 identity federation in AWS IAM Identity Center makes the corporate identity provider the federated source for console authentication, so users sign in through the IdP rather than with AWS-managed credentials (B). However, federation alone does not prevent someone from creating an IAM user with a console password and logging in directly, so an SCP that denies iam:CreateLoginProfile and iam:UpdateLoginProfile is attached to enforce the requirement at the organization level (E). An explicit SCP deny sits above all identity-based policies and cannot be overridden, so no principal in the organization can establish a password-based IAM user login, which makes corporate IdP authentication the only console path.

Why the Other Options Are Wrong

A proposes using GuardDuty with a delegated administrator to deny IAM user logins. GuardDuty is a threat detection service that generates findings; it has no ability to deny an authentication method. C proposes creating a permissions boundary in IAM Identity Center to deny password logins for IAM users; a permissions boundary limits the maximum permissions of a principal and does not govern IAM user console credentials, so it cannot achieve this. D proposes creating IAM groups in the management account to apply consistent permissions, which manages authorization rather than authentication and does not force IdP logins. B and E are the correct combination.

Community Comment Notes

Community voted B,E (82), with B,C an 18 percent minority. Commenters agreed that B establishes SAML federation with the corporate IdP and that E enforces the requirement by preventing creation of IAM user login profiles, with KaranNishad supplying the exact SCP statement denying iam:CreateLoginProfile and iam:UpdateLoginProfile.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide