1 Answer
- Newest
- Most votes
- Most comments
0
Desktop Client vs Browser Access Security Considerations Existing Policy Protection - With your current restrictive policy (disabling file_upload, file_download, printing_to_local_device, copy_to_local_device), most additional security risks are already mitigated. However, there are nuanced differences to consider: Key Differences
Local System Integration
- Desktop client has deeper system-level access
- Browser access is more sandboxed and isolated
- Desktop client can potentially interact more directly with local resources
Potential Additional Security Considerations
- Background process persistence
- System tray/notification interactions
- Potential for additional local caching
- More complex authentication token management
Recommended Verification Steps
- Confirm policy enforcement across both access methods
- Review AWS documentation for specific desktop client security configurations
- Consider additional logging and monitoring for desktop client access
- Validate that your existing restrictive policy fully translates to desktop client
Recommendation
- While your current policy provides strong protection, I recommend:
- Conducting a comprehensive security assessment
- Enabling additional logging for desktop client access
- Periodically reviewing access logs and configurations
Relevant content
asked 3 years ago
asked 2 years ago
- AWS OFFICIALUpdated 4 months ago
