A company uses an AWS Organizations organization to manage multiple AWS accounts. Users access the AWS accounts by using IAM users and secret access keys. A security team requires that all account access use temporary security credentials that expire after 60 minutes. Users must use a SAML-based identity provider (IdP) to access the accounts.
Which solution meets these requirements?
A Enable access to the AWS Security Token Service (AWS STS). Ensure that users run the get-session-token AWS CLI command with an appropriate duration. Require users to use STS temporary credentials to access AWS accounts. B Set up AWS IAM Identity Center and configure an external IdP. Configure permission sets that allow the access that the users require. Configure a session duration limit. Require the users to retrieve SSO credentials by using the AWS CLI. Remove the IAM users from the AWS accounts. C Set up AWS Secrets Manager and Amazon Cognito in each AWS account. Configure a Cognito identity pool to use an external IdP and connect to Secrets Manager. Enable managed secret rotation in Secrets Manager. Ensure that the users run the get-secret-value AWS CLI command to access the AWS accounts. D Enable AWS IAM Roles Anywhere in the organization management account. Ensure that users install the credential helper tool. Configure IAM roles within the management account with an appropriate session duration. Ensure that the users retrieve temporary credentials from the credential helper tool to access the AWS accounts. Show Answer Answer Explanation AWS IAM Identity Center provides centralized access management for multiple AWS accounts, can connect to an existing SAML 2.0 identity provider, and grants account permissions through permission sets. IAM Identity Center CLI authentication supplies temporary credentials, while the permission-set session duration can be configured to 60 minutes. Removing IAM users removes the long-term access keys that violate the requirement.
Learn more
Community Discussion