Your organization wants employees to sign in once with the corporate identity provider and then access multiple AWS accounts and third‑party SaaS applications that support SAML 2.0. Which AWS service and protocol should be used?
A. AWS Single Sign-On (SSO) natively supports SAML 2.0-based applications, allowing users to authenticate once with their corporate IdP and access both AWS accounts and SAML-enabled SaaS applications.
B. Amazon Cognito User Pools should be used for enterprise SSO because they support OIDC and SAML federation and are designed for workforce identity management across AWS accounts.
C. AWS IAM Identity Federation with individual SAML providers should be configured in each AWS account independently, since AWS SSO does not support multi-account access through a single portal.
D. AWS Directory Service Simple AD provides a browser-based SSO portal that federates with SAML 2.0 applications and manages access assignments across AWS accounts in the organization.
AWS Single Sign‑On (SSO) integrates directly with SAML 2. 0 identity providers and provides a unified portal for workforce access to AWS accounts and SAML‑enabled applications.