nerdexam
Adobe

AD0-E117 · Question #16

Refer to the exhibit. A customer has SSO on its AEM Author environment using Adobe IMS, which is integrated with the customer's IDP using SAML The customer plans to roll out a new secured website on…

The correct answer is A. Integrate AEM Publisher using SAML with Adobe IMS. Option A is correct because the existing architecture already uses Adobe IMS as the federation broker between AEM Author and the customer's IDP - extending this same SAML-via-Adobe IMS integration to AEM Publisher maintains architectural consistency and leverages Adobe's…

Design and Architecture

Question

Refer to the exhibit. A customer has SSO on its AEM Author environment using Adobe IMS, which is integrated with the customer's IDP using SAML The customer plans to roll out a new secured website on AEM where SSO authentication is required for end users. The end user accounts are also managed in the customer's existing IDP. How should the Architect set up the authentication for the website?

Exhibits

AD0-E117 question #16 exhibit 1
AD0-E117 question #16 exhibit 2

Options

  • AIntegrate AEM Publisher using SAML with Adobe IMS
  • BSet up CUG and use User Synchronisation from Author to Publisher
  • CIntegrate AEM Publisher using SAML directly with the IDP
  • DIntegrate AEM Publisher using oAuth with Adobe IMS

How the community answered

(38 responses)
  • A
    74% (28)
  • B
    8% (3)
  • C
    13% (5)
  • D
    5% (2)

Explanation

Option A is correct because the existing architecture already uses Adobe IMS as the federation broker between AEM Author and the customer's IDP - extending this same SAML-via-Adobe IMS integration to AEM Publisher maintains architectural consistency and leverages Adobe's recommended pattern for securing publish environments with SSO. Option B is wrong because CUG (Closed User Groups) is an access control mechanism, not an authentication solution, and syncing users from Author to Publisher does not establish SSO for end users. Option C is wrong because bypassing Adobe IMS to connect Publisher directly to the IDP creates a fragmented architecture where Author and Publisher use different authentication paths, contradicting the existing setup and Adobe's recommended approach. Option D is wrong because oAuth with Adobe IMS is suited for service-to-service or API-level authentication, not browser-based end-user SSO, which requires SAML.

Memory tip: Think of Adobe IMS as the central hub in the wheel - both Author and Publisher should connect through it, not around it. If Author uses SAML → Adobe IMS → IDP, Publisher should follow the exact same spoke.

Topics

#Adobe IMS#SAML Authentication#SSO#AEM Publisher

Community Discussion

No community discussion yet for this question.

Full AD0-E117 Practice