AWS Quicksight Access - via Amazon Active Directory AND IAM Roles

0

We are looking to expand services via AWS Quicksight, our use case would include Amazon subsidiary users who can be both in Amazon network and not. My question is it possible to setup new AWS accounts to allow BOTH Active Directory (for in network users) and unique IAM roles (for subsidiary/off-network users)? If not what are the options to allow this type of access using SSO where possible.

3 Risposte
0

Hello, Thank you for your question. Yes it is possible to set both active directory and IAM roles within an AWS account. You can assign Active directory users and groups to IAM roles and grant permissions to these roles. You can also use Quicksight with IAM.

Here are the links with more information about Active directory: https://aws.amazon.com/blogs/security/introducing-aws-directory-service-for-microsoft-active-directory-standard-edition/ https://docs.aws.amazon.com/quicksight/latest/user/external-identity-providers.html

Here's the link if you need further assistance using Quicksight with IAM policies and roles: https://docs.aws.amazon.com/quicksight/latest/user/security_iam_service-with-iam.html

Josie_K
con risposta 2 anni fa
0

Hello, I have the same concern, only what would happen if I have my quicksight configured by SSO and I want to enter the mobile application with IAM users or the quicksight console by IAM users without being redirected to SSO?

hcantos
con risposta un anno fa
0

No you cannot configure a single QuickSight account to use both AD and IAM users. If you use AD it is all or nothing. If you use IAM you can federate users from multiple Identity Providers though (some internal some external for instance).

con risposta un anno fa

Accesso non effettuato. Accedi per postare una risposta.

Una buona risposta soddisfa chiaramente la domanda, fornisce un feedback costruttivo e incoraggia la crescita professionale del richiedente.

Linee guida per rispondere alle domande