A. Create IAM users for each identity provider (IdP) user to allow access to the AWS environment.
B. Define assertions that map the company’s identity provider (IdP) users to IAM roles.
C. Create IAM roles with a trust policy that lists the SAML provider as the principal.
D. Create IAM users, place them in a group named SAML, and grant them necessary IAM permissions.
E. Grant identity provider (IdP) users the necessary IAM permissions to be able to log in to the AWS environment.

- Awsexamhub website is not related to, affiliated with, endorsed or authorized by Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.