A. The IAM user’s permissions policy has allowed the use of SAML federation for that user.
B. The IAM roles created for the federated users’ or federated groups’ trust policy have set the SAML provider as the principal.
C. Test users are not in the AWSFederatedUsers group in the company’s IdR.
D. The web portal calls the AWS STS AssumeRoleWithSAML API with the ARN of the SAML provider, the ARN of the IAM role, and the SAML assertion from IdR.
E. The on-premises IdP’s DNS hostname is reachable from the AWS environment VPCs.
F. The company’s IdP defines SAML assertions that properly map users or groups in the company to IAM roles with appropriate permissions.
- Awsexamhub website is not related to, affiliated with, endorsed or authorized by Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.
Join the Discussion
You must be logged in to post a comment.