Identity Center 1 Flashcards
High Level
What is IAM IC all about?
Streamline managing how humans access all your company’s AWS accounts
High Level
How does it simplify managing humans?
Each AWS account doesn’t have an IAM User for each human - only one in IAM IC
High Level
How do I “turn on” Identity Center?
Must use root creds in your account, need Organizations turned on.
High Level
What can you configure in IC for your users to access?
important
Both AWS accoucnts and other External Applications
High Level
2 highest-level features?
important
Single sign-on to many things from one identity provider; centralized permission management
High Level
How much does IC cost?
Free
Workforce Identity
Question talking about workplace identity federation, preferred soln?
important
IC (over any other methods like granting IAM Users to everyone)
Workforce Identity
Question talking about web identity federation, preferred soln?
important
Not IC! Probably Cognito
Workforce Identity
Why prefer IC over other (older) things like SAML federation?
important
IC manages permissions across all AWS accounts and external programs.
Workforce Identity
What are workforce identities?
Human users in your company.
Workforce Identity
Where do you store workforce identities?
Either on-prem in your own AD, or in Identity Center as users & groups
Identity Sources
Three places you can store users and groups?
Inside IC, Active Directory, external Identity Provider (IdP)
Identity Sources
Examples of Active Directory?
Refers to AWS-managed AD or AD Connector
Identity Sources
Examples of external IdP?
Azure AD, Google Workspace
Identity Sources
How do users sign-in if you manage Workforce Identities in IC?
Use the AWS access portal
Identity Sources
How do users sign-in if you manage Workforce Identities in IC?
Use the AWS access portal
Identity Sources
How do users sign-in if you manage Workforce Identities in an IdP?
Use the IdP’s signin page, and are redirected to the AWS access portal (already logged-in)
Identity Sources
High-level how do you use an Identity Source?
Synchronize users and groups from your IS into IAM IC.
Identity Sources
Why important to pick your identity source when enabling Identity Center?
Changing later may remove all your current users in Identity Center.
Identity Sources
What happens if you switch from internally-managed workforce identities to an external IdP?
Same-named usernames work, others are stranded.
Identity Sources
What happens if you switch from one external IdP to another?
If they both send the same SAML assertions and usernames match, all app assignments still work.
Identity Sources
What happens if you switch to/from AD and an external IdP?
All workforce identies are deleted from Identity Center.