Use IAM Identity Center with the external IdP and permission sets for scalable multi-account RBAC

Answer Correct answer: C — IAM Identity Center with the external IdP and permission sets scales RBAC across 100+ accounts.

A company uses AWS Organizations. The company has more than 100 AWS accounts and will increase the number of accounts. The company also uses an external corporate identity provider (IdP). The company needs to provide users with role-based access to the accounts. The solution must maximize scalability and operational efficiency. Which solution will meet these requirements?

  1. In each account, create a set of dedicated IAM users. Ensure that all users assume these IAM users through federation with the existing IdP.
  2. Deploy an IAM role in a central identity account. Allow users to assume the role through federation with the existing IdP. In each account, deploy a set of IAM roles that match the desired access patterns. Include a trust policy that allows access from the central identity account. Edit the permissions policy for the role in each account to match user access requirements.
  3. Enable AWS IAM Identity Center. Integrate IAM Identity Center with the company's existing IdP. Create permission sets that match the desired access patterns. Assign permissions to match user access requirements. Correct Answer
  4. In each account, deploy a set of IAM roles that match the desired access patterns. Create a trust policy with the existing IdP. Update each role's permissions policy to use SAML-based IAM condition keys that are based on user access requirements.

Community Votes

C
82%
B
18%

82% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

IAM Identity Center is purpose-built for centralized, scalable access across many accounts. By federating the existing IdP and defining permission sets (which become IAM roles in each assigned account), access is governed from one place and scales as accounts are created, avoiding the per-account identity sprawl of IAM users or hand-built role trust policies.

With over 100 growing accounts and an external corporate IdP, the company needs scalable role-based access. AWS IAM Identity Center integrates with the external IdP via SAML/SCIM and uses permission sets assigned to accounts to grant principals role-based access, managed centrally and automatically propagated as accounts are added—far more operationally efficient than per-account IAM users or roles.

Creating dedicated IAM users in every account (option A)—with 100+ and growing accounts this becomes unmanageable. Or building per-account IAM roles with IdP trust policies and manually editing permission policies (option B/D), which does not scale and adds heavy operational overhead.

Community Discussion (7 comments)

navid1365 👍 3 Selected: C
C: AWS IAM Identity Center (successor to AWS Single Sign-On (SSO)) is designed to provide centralized access management across multiple AWS accounts and integrates with external identity providers. This makes it scalable and efficient for managing access to a large number of AWS accounts.
kupo777 👍 4
C is correct. Choice B is too operationally inefficient to realize given that there are over 100 AWS accounts and the number of accounts will grow.
Arad 👍 3 Selected: C
C is correct.
cumzle_com 👍 1 Selected: B
key word : The company needs to provide users with role-based access to the accounts
RaniaSaeedB 👍 3 Selected: C
This solution provides centralized management, reducing operational overhead. IAM Identity Center (AWS Single Sign-On) scales easily across multiple accounts and integrates well with external IdPs. It allows for centralized creation and management of permission sets, ensuring efficient and secure role-based access.
PegasusForever 👍 3
C - Option B involves a more complex and less scalable setup. Option C, on the other hand, offers a centralized, scalable, and efficient solution for managing role-based access across a large and growing number of AWS accounts. The use of AWS IAM Identity Center simplifies the integration with external IdPs and provides a streamlined approach to managing permissions, making it the preferred choice for maximizing scalability and operational efficiency.
aescudero51 👍 1 Selected: B
Answer is B A. Dedicated IAM Users: This creates a massive number of identities to manage, becoming cumbersome and error-prone as the number of accounts increases. C. IAM Identity Center: While IAM Identity Center offers centralized management, it's a separate service that might introduce additional complexity in this scenario. D. SAML-based IAM condition keys: While this allows for fine-grained access control, it can become complex to manage permissions policies for a large number of roles across accounts. Therefore, option B provides the best balance between scalability, operational efficiency, and leveraging existing infrastructure for user access control.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

IAM Identity Center provides centralized, scalable role-based access across a large and growing multi-account organization. Integrating it with the existing external IdP lets users sign in through their corporate identity, and permission sets define the access patterns that are automatically provisioned as IAM roles in each assigned account. This maximizes scalability and minimizes operational effort as accounts increase.

Why the Other Options Are Wrong

A creates IAM users in every account, which is unmanageable at 100+ and growing accounts. B and D deploy per-account IAM roles and manually maintain trust policies and permission policies, which is operationally inefficient and does not scale well. C's centralized model is explicitly the efficient, scalable choice the scenario demands.

Community Comment Notes

Community favored C (82 votes), noting B is "too operationally inefficient" for 100+ growing accounts and that Identity Center (SSO) is designed for centralized, scalable multi-account RBAC with external IdP integration. A minority argued B for granular control but conceded scalability concerns.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide