Are sso-directory role permissions used for anything still?

0

Are "sso-directory" role permissions used for anything still? From what I see the Identity Store has taken over the SSO directory's role and there are separate "identitystore" role permissions. Are they roughly equivalent?

1回答
0

sso-directory is the services prefix for the AWS IAM identity Center directory (successor to AWS Single Sign-On directory or AWS SSO directory) , while identitystore is the services prefix for the AWS Identity Store (legacy term: AWS SSO store or AWS SSO identity store).

So both exist, but are used for different things.

To give an example:

  • identitystore:CreateGroup would grant permission to create a group in the specified IdentityStore
  • sso-directory:CreateGroup would grant permission to create a group in the directory that AWS IAM Identity Center provides by default
AWS
回答済み 10ヶ月前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ