SSO : write a permission that limit actions to all accounts in OU

0

In IAM identity center (AWS SSO), I would like to create a permission that authorizes actions only on accounts belonging to a specific OU. What resources and conditions should I put in?

1回答
0

Hello.

As far as I know, I don't think it's possible to allow an IAM identity center user to perform actions only on a specific OU.
IAM identity center users are allowed to perform actions on the AWS accounts they have been granted access to.
Therefore, I think it would be a good idea to not link the IAM identity center user to any AWS account other than the required AWS account.
https://docs.aws.amazon.com/singlesignon/latest/userguide/useraccess.html

profile picture
エキスパート
回答済み 3ヶ月前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ