AnswerCorrect answer: B — IAM Identity Center with the external IdP as identity source and permission sets centrally manages org account and app access.
A company is planning to create an organization by using AWS Organizations. The company needs to integrate user management with the company’s external identity provider (IdP). The company also needs to centrally manage access to all of its AWS accounts and applications from the organization’s management account. Which solution will meet these requirements?
Configure AWS Directory Service with the external IdP. Create IAM policies and associate them with users from the external IdP.
Enable AWS IAM Identity Center and use the external IdP as the identity source. Create permission sets and account assignments by using IAM Identity Center. Correct Answer
Configure AWS Identity and Access Management (IAM) to use the external IdP as an IdP. Create IAM policies and associate them with users from the external IdP.
Enable Amazon Cognito in the organization’s management account. Create an identity pool and associate it with the external IdP. Create IAM roles and associate them with the identity pool.
Community Votes
B
83%
D
17%
83% of anonymous learners picked answer B.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
IAM Identity Center is purpose-built to be the central access hub for an Organization: set the external IdP as the identity source, then define permission sets assigned to accounts and applications. This single control plane covers both AWS account access and connected applications, which IAM users, Directory Service, or Cognito do not provide for org-wide account management.
The company is creating an AWS Organization and needs to federate its external IdP for user management while centrally controlling access to all AWS accounts and applications from the management account. IAM Identity Center uses the external IdP as the identity source (SAML/SCIM) and provides permission sets and account assignments that grant role-based access across every account and to integrated applications, all managed centrally.
Using Amazon Cognito (option D), which is for application end-user authentication, not centralized management of AWS account access across an Organization. Or wiring IAM users to an external IdP (option C), which does not scale centrally across many accounts like Identity Center.
Community Discussion (5 comments)
molerowan👍 1Selected: B
Integration with External IdP: IAM Identity Center supports SAML 2.0 and SCIM for seamless integration with external identity providers (e.g., Azure AD, Okta). Users authenticate via the corporate IdP and access AWS resources through the AWS access portal. Centralized Access Management: Permission Sets: Define roles (e.g., ReadOnly, Administrator) in the management account and assign them to users/groups from the external IdP. These sets apply across all AWS accounts in the organization. Account Assignments: Assign users/groups to specific AWS accounts with predefined permissions, eliminating per-account IAM role configuration. AWS Organizations Compatibility: When enabled in the management account, IAM Identity Center becomes the central hub for managing access across all member accounts
Pmktechno👍 1Selected: B
AWS IAM Identity Center (formerly AWS Single Sign-On): This service allows you to centrally manage access to multiple AWS accounts and applications. It integrates seamlessly with external IdPs, providing a unified identity management solution. Permission Sets and Account Assignments: IAM Identity Center enables you to create permission sets that define the permissions for users and groups. You can then assign these permission sets to users and groups across your AWS accounts, ensuring consistent access management. This approach provides a robust and scalable solution for managing user access and permissions across your AWS environment.
IPLogic👍 2Selected: B
The best solution for integrating user management with an external identity provider (IdP) and centrally managing access to all AWS accounts and applications is B. Enable AWS IAM Identity Center and use the external IdP as the identity source. Create permission sets and account assignments by using IAM Identity Center. AWS IAM Identity Center (formerly AWS Single Sign-On) allows you to connect your external IdP, such as Okta or Microsoft Entra ID, using SAML 2.0 or SCIM protocols1. This setup enables centralized management of user access across all AWS accounts and applications within your organization
HappyG👍 1Selected: B
Amazon Cognito is intended for managing access to user-facing applications, not for centralized management of AWS accounts and resources in an organization so D doesn't work.
jdx000👍 1Selected: D
D is more scalable
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
IAM Identity Center integrates the external IdP as the identity source and centrally governs access to all Organization accounts and to applications via permission sets and account assignments, managed from the management account. This meets both the IdP-federation and central-access-management requirements in one service.
Why the Other Options Are Wrong
A (Directory Service with the IdP) adds a directory and IAM policies but lacks the centralized multi-account permission-set model. C (IAM with external IdP) and D (Cognito) target application or single-account access; Cognito is for user-facing app auth, not org-wide AWS account administration. B is the consolidated solution.
Community Comment Notes
Community favored B (83 votes). Commenters noted Cognito is for application access, not centralized AWS account management, and that Identity Center with the external IdP plus permission sets is the designed approach. A minority picked D for perceived scalability, but D does not manage account access centrally.