Managing permissions to IAM roles centrally

0

Do we have any way using which we can assign policies to IAM roles in multiple AWS accounts centrally?

3回答
2

No, there is no such mechanism, with which you can assign policies to IAM roles in multiple accounts.

Closest thing you can do is described here at Using identity-based policies (IAM policies) for AWS Organizations.

Within an account, you can create customer managed policy and use that in as many role as you want but that can't be shared across the multiple accounts.

Since your use case is not mentioned here, I could think of role chaining as well, where one role can assume another role but that would require trust relationship to be updated for target account role. Refer Role chaining and https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_terms-and-concepts.html#iam-term-role-chaining.

Hope this helps.

Comment here if you have additional questions, happy to help.

Abhishek

profile pictureAWS
エキスパート
回答済み 8ヶ月前
0

Yes AWS IAM Identity Center helps you securely create or connect your workforce identities and manage their access centrally across AWS accounts and applications. IAM Identity Center is the recommended approach for workforce authentication and authorization on AWS for organizations of any size and type.

You can learn more about AWS Identity Center, in AWS documentation. --> https://docs.aws.amazon.com/singlesignon/latest/userguide/what-is.html

In addition, you can read my blog on Strengthening Security in AWS Control Tower through Centralized IAM Identity Center. --> https://www.awsyarn.com/strengthening-security-in-aws-control-tower-through-centralized-iam-identity-center/

profile picture
回答済み 8ヶ月前
profile pictureAWS
エキスパート
レビュー済み 8ヶ月前
profile pictureAWS
エキスパート
レビュー済み 8ヶ月前
0
profile pictureAWS
エキスパート
kentrad
回答済み 8ヶ月前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ