It should be B and C.
In IAM, you create one or more IAM roles. In the role's trust policy, you set the SAML provider as the principal, which establishes a trust relationship between your organization and AWS.
B | C are the answers
You first create the IAM roles , setting the SAML provider as trusted (C), then you define assertions that map users to the IAM roles
B. Define assertions that map the company's identity provider (IdP) users to IAM roles.
C. Create IAM roles with a trust policy that lists the SAML provider as the principal.
Seem correct
C&B:
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_saml.html
See Steps 4 & 5
4. In IAM, you create one or more IAM roles. In the role's trust policy, you set the SAML provider as the principal, which establishes a trust relationship between your organization and AWS.
5. n your organization's IdP, you define assertions that map users or groups in your organization to the IAM roles.
B&C are correct:
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_enable-console-saml.html
B is in Step 5 : In your organization's IdP, you define assertions that map users or groups in your organization to the IAM roles.
C is in step 4: In IAM, you create one or more IAM roles. In the role's trust policy, you set the SAML provider as the principal, which establishes a trust relationship between your organization and AWS. The role's permission policy establishes what users from your organization are allowed to do in AWS.
B & C.
- In your organization's IdP, you define assertions that map users or groups in your organization to the IAM roles. Note that different users and groups in your organization might map to different IAM roles.
- In IAM, you create one or more IAM roles. In the role's trust policy, you set the SAML provider as the principal, which establishes a trust relationship between your organization and AWS. The role's permission policy establishes what users from your organization are allowed to do in AWS
from the link:
"create an IAM role that establishes a trust relationship between IAM and your organization's IdP. This role must identify your IdP as a principal (trusted entity) for purposes of federation.
After you create the role, inform your SAML IdP about AWS as a service provider
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
coolboylqy
Highly Voted 1 year, 3 months agomukeshs
Highly Voted 1 year, 2 months agoasfsdfsdf
Most Recent 10 months, 1 week agoRicardoD
1 year, 1 month agoabhishek_m_86
1 year, 1 month agojackdryan
1 year, 1 month agoA3A3
1 year, 1 month agowaterzhong
1 year, 2 months agoshammous
1 year, 2 months agoMrKhan
1 year, 2 months agoAWS_Noob
1 year, 2 months agoThoseWereTheDays
1 year, 2 months agoshammous
1 year, 2 months agorby293
1 year, 2 months agoawsnoob
1 year, 2 months agogretch
1 year, 2 months agosaumenP
1 year, 2 months agoAbhishekGupta
1 year, 2 months agoTJarriault
1 year, 3 months ago