Instiq
Chapter 4 · Identity and Access Management·v2.0.0·Updated 6/5/2026·~8 min

What's changed: Deepened SCS-C02 Chapter 4 (added comparison tables, scenarios, FAQs, exam traps, deep-dive paragraphs to each section; localized figures to Japanese)

4.4In-scope services for identity and access management

Key points

A roundup of in-scope SCS-C03 services for identity and access management.

4.4.1In-scope services for identity and access management

For identity and access management, beyond IAM/IAM Identity Center/STS/AssumeRole, know: Amazon Cognito (end-user authentication for web/mobile apps), AWS Directory Service (managed Active Directory), and Amazon Verified Permissions (externalize application authorization with the Cedar policy language).

Diagram grouping app authentication (Amazon Cognito), directory (AWS Directory Service / managed AD), and externalized authorization (Amazon Verified Permissions / Cedar).
Identity/access management services

4.4.2Section summary

  • Auth/directory: Cognito (app user auth) / Directory Service (managed AD)
  • Externalized authz: Verified Permissions (fine-grained authz via Cedar)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Which service decouples authorization from app code and centrally manages fine-grained access control with the Cedar policy language?

Q2. Which provides sign-up/sign-in and a user directory for end users of web/mobile apps?

Check your understandingPractice questions for Chapter 4: Identity and Access Management

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.