1 Answers
0
Accepted Answer
You should check out the blog post on best practices with OU management. There are suggestions for both sandbox environments and logging: https://aws.amazon.com/blogs/mt/best-practices-for-organizational-units-with-aws-organizations/
Check out centralized CloudTrail for logging and auditing. It's a widely adopted best practice. It helps the management account make sure everything is logged (and doesn't let member accounts turn it off).
For IAM role usage. There are many approaches customers can take. I don't have Terraform examples. Stacksets provides easy integration for rollout of IAM roles.
answered 2 years ago
Relevant questions
IAM users/roles/groups policies reports
Accepted Answerasked 7 months agohow can i quickly troubleshoot IAM permission for a service
asked 7 months agoIdentify in-built or default IAM Roles
Accepted Answerasked 6 months agoIAM as code - centralize the management of IAM roles and policies in a multi-account organization
Accepted Answerasked 2 years agoLimit scope of AWS Managed IAM Policies?
Accepted Answerasked 8 months agoIAM roles rightsizing
Accepted Answerasked 2 months agoResolving the error "Ensure IAM policies are attached only to groups or roles"
asked 2 months agoFinding the right policy in IAM
asked a month agoSpecify Individual Instance In Trust Policy Of IAM Role
Accepted Answerasked 3 months agoHow to use IAM users, groups and roles with SSO
asked 2 months ago