Q5Identity and Access Management
HOTSPOT - A security engineer needs to implement AWS IAM Identity Center with an exlemai identity provider (IdP). Select and order the correct steps from the following list to meet this requirement. Select each step one time or not at all. Configure the external IdP as the identity source in IAM Identity Center. Create an IAM role that has a trust policy that specifics the IdP's API endpoint. Enable automatic provisioning in IAM Identity Center settings Enable automatic provisioning in the external IdP. Obtain the SAML metadata from IAM Identity Center. Obtain the SAML metadata from the external IdP.
← → navigate · a answer
Discussion · 3
3
Obtain the SAML metadata from IAM Identity Center
Obtain the SAML metadata from the external IdP
Configure the external IdP as the identity source in IAM Identity Center
SAML setup = metadata exchange first, configuration second, provisioning last
1. IAM Identity Center → export metadata
2. Configure IdP with it
3. IdP → export metadata
4. Configure IAM Identity Center with IdP
5. Enable provisioning (both sides)
2
1. Obtain the SAML metadata from the external IdP
2. Configure the external IdP as the identity source in IAM Identity Center
3. Enable provisioning in IAM Identity Center settings
1
https://docs.aws.amazon.com/singlesignon/latest/userguide/how-to-connect-idp.html