QuestionQ10

Identity and Access Management

A company uses an AWS Organizations organization to manage multiple AWS accounts. Users access the AWS accounts by using IAM users and secret access keys. A security team requires that all account access use temporary security credentials that expire after 60 minutes. Users must use a SAML-based identity provider (IdP) to access the accounts.

Which solution meets these requirements?

Explanation

AWS IAM Identity Center provides centralized access management for multiple AWS accounts, can connect to an existing SAML 2.0 identity provider, and grants account permissions through permission sets. IAM Identity Center CLI authentication supplies temporary credentials, while the permission-set session duration can be configured to 60 minutes. Removing IAM users removes the long-term access keys that violate the requirement.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!