SOA-C02 · Question #8
A company's SysOps administrator uses AWS IAM Identity Center (AWS Single Sign-On) to connect to an Active Directory. The SysOps administrator creates a new account that all the company's users need…
The correct answer is D. Correct the permissions on the Active Directory group so that IAM Identity Center has read. You need to give IAM Identity Center access to read the AD group so it can logically identify users who are members and grant them access to the new account.
Question
A company's SysOps administrator uses AWS IAM Identity Center (AWS Single Sign-On) to connect to an Active Directory. The SysOps administrator creates a new account that all the company's users need to access. The SysOps administrator uses the Active Directory Domain Users group for permissions to the new account because all users are already members of the group. When users try to log in, their access is denied. Which action will resolve this access issue?
Options
- ACreate a new group. Add users to the new group to provide access.
- BCorrect the time on the Active Directory domain controllers.
- CRemove the account. Re-add the account to the organization that is integrated with IAM Identity
- DCorrect the permissions on the Active Directory group so that IAM Identity Center has read
How the community answered
(50 responses)- A6% (3)
- B2% (1)
- C8% (4)
- D84% (42)
Explanation
You need to give IAM Identity Center access to read the AD group so it can logically identify users who are members and grant them access to the new account.
Topics
Community Discussion
No community discussion yet for this question.