A school district wants teachers and staff to use Google Workspace identities for AWS Management Console access. Which approach is appropriate?
Select an answer to reveal the explanation.
Short Explanation
Teachers already have Google Workspace logins—federate those into AWS instead of cloning passwords into IAM. Identity Center or SAML roles keep the district directory as the source of truth. Syncing passwords or sharing one IAM user undoes that benefit.
Full Explanation
External identity providers should federate into AWS using standards-based federation through AWS IAM Identity Center or IAM SAML roles. Password synchronization into IAM users is insecure and operationally fragile. Shared IAM users and distribution of root credentials violate least privilege and accountability for workforce console access.