nerdexam
Amazon

SAA-C03 · Question #747

A company is using an Active Directory based Identity provider (IdP) service that supports SAML 2.0. The company wants to use the existing authentication solution to access the AWS Management…

The correct answer is D. Configure AWS IAM Identity Center to use an external IdP. Provide the SAML metadata from the. AWS IAM Identity Center (formerly AWS Single Sign-On) can be configured to use an external SAML 2.0 identity provider, such as Active Directory. By providing the SAML metadata, users can access the AWS Management Console using their existing corporate credentials without…

Submitted by akirajp· Mar 4, 2026Design Secure Architectures

Question

A company is using an Active Directory based Identity provider (IdP) service that supports SAML 2.0. The company wants to use the existing authentication solution to access the AWS Management Console. A solutions architect needs to configure federated authentication. Which solution will meet these requirements?

Options

  • AUse AWS Verified Access to create a new trust provider. Connect the existing Active Directory
  • BUse Amazon Cognito to create an identity pool. Add the existing Active Directory IdP to the user
  • CUse AWS Amplify to configure a custom authentication backend by using Amplify Auth. Set up an
  • DConfigure AWS IAM Identity Center to use an external IdP. Provide the SAML metadata from the

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    6% (2)
  • D
    88% (28)

Explanation

AWS IAM Identity Center (formerly AWS Single Sign-On) can be configured to use an external SAML 2.0 identity provider, such as Active Directory. By providing the SAML metadata, users can access the AWS Management Console using their existing corporate credentials without creating new AWS accounts or credentials.

Community Discussion

No community discussion yet for this question.

Full SAA-C03 Practice