AWS Certified Solutions Architect – Professional — Question 868

A company is building an AWS landing zone and has asked a Solutions Architect to design a multi-account access strategy that will allow hundreds of users to use corporate credentials to access the AWS Console. The company is running a Microsoft Active Directory, and users will use an AWS Direct Connect connection to connect to AWS. The company also wants to be able to federate to third-party services and providers, including custom applications.
Which solution meets the requirements by using the LEAST amount of management overhead?

Answer options

Correct answer: B

Explanation

AWS Single Sign-On (now AWS IAM Identity Center) combined with AWS Organizations offers a highly scalable, multi-account access solution with minimal administrative effort. By establishing a two-way Forest trust with AWS Directory Service, on-premises Active Directory users can easily authenticate to AWS. This solution avoids the high management and maintenance overhead of deploying and configuring a self-managed AD FS infrastructure.