Setting up Quicksight Multi Account SSO

0

Hi,

I have a requirement to provide access to Quicksight in multiple AWS accounts via SSO using Google Workspace. I found this guide -> https://aws.amazon.com/blogs/big-data/enable-amazon-quicksight-federation-with-google-workspace/ and was able to successfully configure SSO for one of the accounts.

I would like to know what the process is for configuring SSO for multiple accounts. Can I follow the same guide? and repeat the process on each of the accounts or is there another option like AWS Identify center to consolidate all this?

Any guidance on this is greatly appreciated.

1개 답변
0
수락된 답변

Using IAM Identity Center as a centralized user identity store would be recommended approach as it can scale to fit multi-account approach.

With IAM Identity Center, you can define and assign access across multiple AWS accounts. For example, permission sets create IAM roles and apply IAM policies in multiple AWS accounts, helping to scale the access of your users securely and consistently. When you assign a permission set, IAM Identity Center creates corresponding IAM Identity Center-controlled IAM roles in each account, and attaches the policies specified in the permission set to those roles, which will be used by your federated users.

Kindly refer to this blog for additional information on IAM Identity Center: https://aws.amazon.com/blogs/security/scale-your-workforce-access-management-with-aws-iam-identity-center-previously-known-as-aws-sso/

Kindly use the following guides to implement your solution:

  1. Create an AWS Organization and add relevant member accounts: https://docs.aws.amazon.com/organizations/latest/userguide/orgs_tutorials_basic.html

  2. Use Google Workspace as an external identity provider for AWS IAM Identity Center: https://aws.amazon.com/blogs/security/how-to-use-g-suite-as-external-identity-provider-aws-sso/

  3. Link AWS Identity Center to Amazon Quicksight (using permission set approach): https://docs.aws.amazon.com/prescriptive-guidance/latest/quicksight-access-approach/iam-identity-center.html

  4. Dashboards in Amazon QuickSight can be co-owned by AWS Identity Center users once the two services are linked (from step above): https://docs.aws.amazon.com/quicksight/latest/user/share-a-dashboard-grant-access-users.html

Hope this helps.

AWS
답변함 10달 전
  • Thank you this cleared up things

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠