Identity federation lets users sign in with an existing identity provider — corporate Active Directory, Google, or a SAML IdP — and get temporary AWS access, so you don’t create separate IAM users for everyone.

How it works

The external identity provider authenticates the user; AWS (via STS) issues temporary credentials tied to a role. This avoids managing long-term IAM users and is the standard for enterprise SSO into AWS. The tell is “let corporate/external users access AWS without creating IAM users.”

Test yourself

Practice question

A company wants employees to access AWS using their existing corporate Active Directory credentials, without creating individual IAM users. What enables this?

  1. Creating an IAM user per employee
  2. Identity federation with a role (via STS)
  3. A shared root account
  4. A bucket policy
👉 Click to reveal the answer & explanation

Correct answer: B. Federation lets the corporate IdP authenticate users who then assume a role for temporary AWS credentials — no per-user IAM accounts. Per-employee IAM users (A) don’t scale; sharing root (C) is insecure; a bucket policy (D) controls resource access, not sign-in.

Related topics

AWS IAM · AWS STS · IAM Identity Center

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access