It should be B and C.
In IAM, you create one or more IAM roles. In the role's trust policy, you set the SAML provider as the principal, which establishes a trust relationship between your organization and AWS.
B | C are the answers
You first create the IAM roles , setting the SAML provider as trusted (C), then you define assertions that map users to the IAM roles
B. Define assertions that map the company's identity provider (IdP) users to IAM roles.
C. Create IAM roles with a trust policy that lists the SAML provider as the principal.
Seem correct
C&B:
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_saml.html
See Steps 4 & 5
4. In IAM, you create one or more IAM roles. In the role's trust policy, you set the SAML provider as the principal, which establishes a trust relationship between your organization and AWS.
5. n your organization's IdP, you define assertions that map users or groups in your organization to the IAM roles.
B&C are correct:
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_enable-console-saml.html
B is in Step 5 : In your organization's IdP, you define assertions that map users or groups in your organization to the IAM roles.
C is in step 4: In IAM, you create one or more IAM roles. In the role's trust policy, you set the SAML provider as the principal, which establishes a trust relationship between your organization and AWS. The role's permission policy establishes what users from your organization are allowed to do in AWS.
B & C.
- In your organization's IdP, you define assertions that map users or groups in your organization to the IAM roles. Note that different users and groups in your organization might map to different IAM roles.
- In IAM, you create one or more IAM roles. In the role's trust policy, you set the SAML provider as the principal, which establishes a trust relationship between your organization and AWS. The role's permission policy establishes what users from your organization are allowed to do in AWS
from the link:
"create an IAM role that establishes a trust relationship between IAM and your organization's IdP. This role must identify your IdP as a principal (trusted entity) for purposes of federation.
After you create the role, inform your SAML IdP about AWS as a service provider
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
coolboylqy
Highly Voted 1 year, 1 month agomukeshs
Highly Voted 1 year, 1 month agoasfsdfsdf
Most Recent 8 months, 3 weeks agoRicardoD
1 year agoabhishek_m_86
1 year agojackdryan
1 year agoA3A3
1 year agowaterzhong
1 year agoshammous
1 year agoMrKhan
1 year agoAWS_Noob
1 year agoThoseWereTheDays
1 year agoshammous
1 year agorby293
1 year agoawsnoob
1 year agogretch
1 year agosaumenP
1 year agoAbhishekGupta
1 year, 1 month agoTJarriault
1 year, 1 month ago