nerdexam
Amazon

SAP-C02 · Question #847

Company A recently acquired Company B. Company A requires that Company B use Amazon Workspaces in a separate member AWS account that Company A manages. Company A uses AWS Organizations with all…

The correct answer is D. Enable the creation of account instances in member accounts. Configure an IAM Identity Center. IAM Identity Center now supports per-account “account instances.” By creating one in Company B’s member account and pointing it to Company B’s SAML IdP, WorkSpaces in that account can authenticate solely against Company B’s identity source - without involving Company A’s global…

Submitted by anjalisingh· Mar 6, 2026Design Solutions for Organizational Complexity

Question

Company A recently acquired Company B. Company A requires that Company B use Amazon Workspaces in a separate member AWS account that Company A manages. Company A uses AWS Organizations with all features enabled. Company A also uses AWS IAM Identity Center with a SAML-based identity source for access to Company A's AWS accounts. Company B has its own SAML-based identity provider (IdP). Company A requires that authentication to Workspaces use only Company B's own IdP. Which solution will meet these requirements?

Options

  • AConfigure a Workspaces application from the IAM Identity Center application catalog. Set up the
  • BConfigure IAM Identity Center with a second identity source. Configure attributes for access
  • CConfigure an IAM SAML IdP in the member AWS account. Create IAM roles in the member AWS
  • DEnable the creation of account instances in member accounts. Configure an IAM Identity Center

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    10% (4)
  • C
    15% (6)
  • D
    69% (27)

Explanation

IAM Identity Center now supports per-account “account instances.” By creating one in Company B’s member account and pointing it to Company B’s SAML IdP, WorkSpaces in that account can authenticate solely against Company B’s identity source - without involving Company A’s global instance. This cleanly isolates auth while staying within the Organizations-managed account.

Community Discussion

No community discussion yet for this question.

Full SAP-C02 Practice