Identity Center 1 Flashcards

1
Q

High Level

What is IAM IC all about?

A

Streamline managing how humans access all your company’s AWS accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

High Level

How does it simplify managing humans?

A

Each AWS account doesn’t have an IAM User for each human - only one in IAM IC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

High Level

How do I “turn on” Identity Center?

A

Must use root creds in your account, need Organizations turned on.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

High Level

What can you configure in IC for your users to access?

important

A

Both AWS accoucnts and other External Applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

High Level

2 highest-level features?

important

A

Single sign-on to many things from one identity provider; centralized permission management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

High Level

How much does IC cost?

A

Free

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Workforce Identity

Question talking about workplace identity federation, preferred soln?

important

A

IC (over any other methods like granting IAM Users to everyone)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Workforce Identity

Question talking about web identity federation, preferred soln?

important

A

Not IC! Probably Cognito

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Workforce Identity

Why prefer IC over other (older) things like SAML federation?

important

A

IC manages permissions across all AWS accounts and external programs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Workforce Identity

What are workforce identities?

A

Human users in your company.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Workforce Identity

Where do you store workforce identities?

A

Either on-prem in your own AD, or in Identity Center as users & groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Identity Sources

Three places you can store users and groups?

A

Inside IC, Active Directory, external Identity Provider (IdP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Identity Sources

Examples of Active Directory?

A

Refers to AWS-managed AD or AD Connector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Identity Sources

Examples of external IdP?

A

Azure AD, Google Workspace

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Identity Sources

How do users sign-in if you manage Workforce Identities in IC?

A

Use the AWS access portal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Identity Sources

How do users sign-in if you manage Workforce Identities in IC?

A

Use the AWS access portal

17
Q

Identity Sources

How do users sign-in if you manage Workforce Identities in an IdP?

A

Use the IdP’s signin page, and are redirected to the AWS access portal (already logged-in)

18
Q

Identity Sources

High-level how do you use an Identity Source?

A

Synchronize users and groups from your IS into IAM IC.

19
Q

Identity Sources

Why important to pick your identity source when enabling Identity Center?

A

Changing later may remove all your current users in Identity Center.

20
Q

Identity Sources

What happens if you switch from internally-managed workforce identities to an external IdP?

A

Same-named usernames work, others are stranded.

21
Q

Identity Sources

What happens if you switch from one external IdP to another?

A

If they both send the same SAML assertions and usernames match, all app assignments still work.

22
Q

Identity Sources

What happens if you switch to/from AD and an external IdP?

A

All workforce identies are deleted from Identity Center.