exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 437 discussion

A company's SysOps administrator uses AWS IAM Identity Center (AWS Single Sign-On) to connect to an Active Directory. The SysOps administrator creates a new account that all the company's users need to access.

The SysOps administrator uses the Active Directory Domain Users group for permissions to the new account because all users are already members of the group. When users try to log in, their access is denied.

Which action will resolve this access issue?

  • A. Create a new group. Add users to the new group to provide access.
  • B. Correct the time on the Active Directory domain controllers.
  • C. Remove the account. Re-add the account to the organization that is integrated with IAM Identity Center.
  • D. Correct the permissions on the Active Directory group so that IAM Identity Center has read access.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dspd
4 weeks ago
Selected Answer: D
This identifies the most likely issue. For IAM Identity Center to use Active Directory groups for access control, it needs sufficient permissions to read the group memberships from Active Directory. If the IAM Identity Center service account doesn't have read permissions on the Domain Users group, it won't be able to determine which users should have access, resulting in the described access denied errors.
upvoted 1 times
...
numark
3 months, 3 weeks ago
Selected Answer: A
AWS IAM Identity Center (AWS SSO) integrates with Active Directory (AD) to grant users access to AWS accounts and applications. However, not all AD groups are automatically recognized by IAM Identity Center for permissions management. IAM Identity Center already has read access to AD for user and group information as part of the integration. The problem lies with using the default Domain Users group, not with permissions.
upvoted 1 times
...
tgv
6 months, 2 weeks ago
Selected Answer: D
You need to give IAM Identity Center access to read the AD group so it can logically identify users who are members and grant them access to the new account.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago