A large company has hundreds of AWS accounts. The company needs to provide its employees with access to these accounts. The solution must maximize scalability and operational efficiency. Which solution meets these requirements?
A.
With each AWS account, create dedicated IAM users that employees can assume through federation based upon group membership in their existing identity provider.
B.
Use a centralized account with IAM roles that employees can assume through federation with their existing identity provider. Create a custom authorizer by using AWS SDK to give federated users the ability to assume their target role in the resource accounts.
C.
Implement AWS Control Tower for multi-account management by integrating AWS Single Sign-On with the company's existing identity provider. Create IAM roles for the identity provider to assume.
D.
Configure the IAM trust policies within each account's role to set up a trust back to the company's existing identity provider. Allow users to assume the role based on their SAML token.
This solution allows the company to use AWS Control Tower to centrally manage access to multiple AWS accounts. By integrating AWS Single Sign-On with the company’s existing identity provider, employees can use their existing credentials to sign in to AWS. IAM roles can then be created for the identity provider to assume, allowing employees to access the necessary AWS accounts. C
B seems to be the right answer
Question says there are multiple aws accounts but organization is not mentioned anywhere so we cannot have control tower until ORG is enabled..
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
dumma
Highly Voted 3 years, 8 months ago1awssec
3 years, 7 months agoRaphaello
Most Recent 1 year, 3 months agoToptip
2 years agoITGURU51
2 years, 1 month agoSmartphone
2 years, 4 months agomust_be_rohit
2 years, 5 months agoD2
2 years, 6 months agosapien45
2 years, 9 months agodcasabona
2 years, 10 months agoKaloda
2 years, 10 months agoxaocho
2 years, 11 months agongngngng1999
3 years agotreeli
3 years, 1 month agoslymenk
3 years, 1 month agoRaySmith
3 years, 3 months agoRadhaghosh
3 years, 4 months agoYouYouYou
3 years, 4 months ago