Managing permissions to IAM roles centrally

0

Do we have any way using which we can assign policies to IAM roles in multiple AWS accounts centrally?

bhawna
질문됨 8달 전272회 조회
3개 답변
2

No, there is no such mechanism, with which you can assign policies to IAM roles in multiple accounts.

Closest thing you can do is described here at Using identity-based policies (IAM policies) for AWS Organizations.

Within an account, you can create customer managed policy and use that in as many role as you want but that can't be shared across the multiple accounts.

Since your use case is not mentioned here, I could think of role chaining as well, where one role can assume another role but that would require trust relationship to be updated for target account role. Refer Role chaining and https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_terms-and-concepts.html#iam-term-role-chaining.

Hope this helps.

Comment here if you have additional questions, happy to help.

Abhishek

profile pictureAWS
전문가
답변함 8달 전
0

Yes AWS IAM Identity Center helps you securely create or connect your workforce identities and manage their access centrally across AWS accounts and applications. IAM Identity Center is the recommended approach for workforce authentication and authorization on AWS for organizations of any size and type.

You can learn more about AWS Identity Center, in AWS documentation. --> https://docs.aws.amazon.com/singlesignon/latest/userguide/what-is.html

In addition, you can read my blog on Strengthening Security in AWS Control Tower through Centralized IAM Identity Center. --> https://www.awsyarn.com/strengthening-security-in-aws-control-tower-through-centralized-iam-identity-center/

profile picture
답변함 8달 전
profile pictureAWS
전문가
검토됨 8달 전
profile pictureAWS
전문가
검토됨 8달 전
0
profile pictureAWS
전문가
kentrad
답변함 8달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠