Use Amazon Verified Permissions with Cognito as the identity source for fine-grained authorization
A company runs a custom online gaming application. The company uses Amazon Cognito for user authentication and authorization. A security engineer wants to use AWS to implement fine-grained authorization on resources in the custom application. The security engineer must implement a solution that uses the user attributes that exist in Cognito. The company has already set up a user pool and an identity pool in Cognito. Which solution will meet these requirements?
Community Votes
83% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Verified Permissions is purpose-built for fine-grained, attribute-based authorization (ABAC) and integrates natively with Cognito user pools, parsing the JWT claims (user attributes) to make access decisions (B). IAM roles/policies via the identity pool (A) give coarse role-based access, not attribute-level decisions. RAM (C) shares resources, not authorization logic. IAM users per app user (D) does not scale and is not attribute-driven. B is correct.
For fine-grained authorization based on Cognito user attributes, create a policy store in Amazon Verified Permissions, configure Cognito (the existing user/identity pools) as the identity source, and map Cognito access tokens to the Verified Permissions schema. Verified Permissions then evaluates per-request policies against the user's attributes, going beyond role-based IAM for granular, attribute-based access control in the custom app.
Mapping users to IAM roles/policies via the identity pool (A)—that yields role-based access, not the fine-grained, attribute-based decisions the requirement asks for. Using RAM customer-managed permissions (C)—RAM shares resources across accounts, it is not an authorization engine. Creating IAM users per app user (D)—does not scale and ignores Cognito user attributes. Verified Permissions (B) is the ABAC service.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.