AD0-E117 · Question #16
Refer to the exhibit. A customer has SSO on its AEM Author environment using Adobe IMS, which is integrated with the customer's IDP using SAML The customer plans to roll out a new secured website on…
The correct answer is A. Integrate AEM Publisher using SAML with Adobe IMS. Option A is correct because the existing architecture already uses Adobe IMS as the federation broker between AEM Author and the customer's IDP - extending this same SAML-via-Adobe IMS integration to AEM Publisher maintains architectural consistency and leverages Adobe's…
Question
Refer to the exhibit. A customer has SSO on its AEM Author environment using Adobe IMS, which is integrated with the customer's IDP using SAML The customer plans to roll out a new secured website on AEM where SSO authentication is required for end users. The end user accounts are also managed in the customer's existing IDP. How should the Architect set up the authentication for the website?
Exhibits
Options
- AIntegrate AEM Publisher using SAML with Adobe IMS
- BSet up CUG and use User Synchronisation from Author to Publisher
- CIntegrate AEM Publisher using SAML directly with the IDP
- DIntegrate AEM Publisher using oAuth with Adobe IMS
How the community answered
(38 responses)- A74% (28)
- B8% (3)
- C13% (5)
- D5% (2)
Explanation
Option A is correct because the existing architecture already uses Adobe IMS as the federation broker between AEM Author and the customer's IDP - extending this same SAML-via-Adobe IMS integration to AEM Publisher maintains architectural consistency and leverages Adobe's recommended pattern for securing publish environments with SSO. Option B is wrong because CUG (Closed User Groups) is an access control mechanism, not an authentication solution, and syncing users from Author to Publisher does not establish SSO for end users. Option C is wrong because bypassing Adobe IMS to connect Publisher directly to the IDP creates a fragmented architecture where Author and Publisher use different authentication paths, contradicting the existing setup and Adobe's recommended approach. Option D is wrong because oAuth with Adobe IMS is suited for service-to-service or API-level authentication, not browser-based end-user SSO, which requires SAML.
Memory tip: Think of Adobe IMS as the central hub in the wheel - both Author and Publisher should connect through it, not around it. If Author uses SAML → Adobe IMS → IDP, Publisher should follow the exact same spoke.
Topics
Community Discussion
No community discussion yet for this question.

