Can customers delete the roles "AWSReservedSSO_AdministratorAccess_a9149395f7abc736" and "AWSServiceRoleForSSO" if the linked accounts are in a suspended state?

0

The linked accounts were created as part of the compromised activity and suspended when the service team identified these accounts were Fraudulently created. Can customers delete the roles "AWSReservedSSO_AdministratorAccess_a9149395f7abc736" and "AWSServiceRoleForSSO" now that these linked accounts are in a suspended state? If no, could you please refer me to a public facing document that explains this scenario.

Thank you, Diana Sandhya F

2回答
1
承認された回答

Hi

I would say this heavily depends on if the attacker that opened the accounts have access to the Root user for the account. If the account is suspended then it's not possible to access the account. It is however possible to delete the role in an active account.

Using service-linked roles for IAM Identity Center give instructions on how to manually delete the role, so that is possible.

Closing a member account in your organization states that: If you no longer need a member account in your organization, and want to ensure that no one can accrue charges for it, you can close the account which indicates that it can't be accessed and hence role can't be deleted in this state.

Can I reopen my closed AWS account? give instructions on how to open an closed account, within the 90 day grace period, using the Root user.

So if the attacker still has access to the Root user it is possible that they can reopen the account and delete the role.

I would investigate and create SCP policy that Deny any account to leave the organization and two prevents deleting the roles.

Hope it give some for of answer and help.

profile picture
エキスパート
回答済み 9ヶ月前
1

This document appears to cover the circumstances that you describe https://docs.aws.amazon.com/singlesignon/latest/userguide/using-service-linked-roles.html#delete-slr

When the linked account is removed from your AWS Organisation the service-linked role will be deleted.

You can also delete the service-linked role manually, as long as beforehand you have removed user & group access, and permission sets.

profile picture
エキスパート
Steve_M
回答済み 9ヶ月前
profile pictureAWS
エキスパート
レビュー済み 9ヶ月前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ