AWS Certified SysOps Administrator SOA-C01 – Question661

Which of the following steps are required to configure SAML 2.0 for federated access to AWS? (Choose two.)

A.
Create IAM users for each identity provider (IdP) user to allow access to the AWS environment.
B. Define assertions that map the company’s identity provider (IdP) users to IAM roles.
C. Create IAM roles with a trust policy that lists the SAML provider as the principal.
D. Create IAM users, place them in a group named SAML, and grant them necessary IAM permissions.
E. Grant identity provider (IdP) users the necessary IAM permissions to be able to log in to the AWS environment.

Correct Answer: AB