Identity federation lets users sign in with an existing identity provider — corporate Active Directory, Google, or a SAML IdP — and get temporary AWS access, so you don’t create separate IAM users for everyone.
How it works
The external identity provider authenticates the user; AWS (via STS) issues temporary credentials tied to a role. This avoids managing long-term IAM users and is the standard for enterprise SSO into AWS. The tell is “let corporate/external users access AWS without creating IAM users.”
Test yourself
A company wants employees to access AWS using their existing corporate Active Directory credentials, without creating individual IAM users. What enables this?
- Creating an IAM user per employee
- Identity federation with a role (via STS)
- A shared root account
- A bucket policy
👉 Click to reveal the answer & explanation
Correct answer: B. Federation lets the corporate IdP authenticate users who then assume a role for temporary AWS credentials — no per-user IAM accounts. Per-employee IAM users (A) don’t scale; sharing root (C) is insecure; a bucket policy (D) controls resource access, not sign-in.
Related topics
AWS IAM · AWS STS · IAM Identity Center
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first