AWS Quicksight Access - via Amazon Active Directory AND IAM Roles

0

We are looking to expand services via AWS Quicksight, our use case would include Amazon subsidiary users who can be both in Amazon network and not. My question is it possible to setup new AWS accounts to allow BOTH Active Directory (for in network users) and unique IAM roles (for subsidiary/off-network users)? If not what are the options to allow this type of access using SSO where possible.

3 回答
0

Hello, Thank you for your question. Yes it is possible to set both active directory and IAM roles within an AWS account. You can assign Active directory users and groups to IAM roles and grant permissions to these roles. You can also use Quicksight with IAM.

Here are the links with more information about Active directory: https://aws.amazon.com/blogs/security/introducing-aws-directory-service-for-microsoft-active-directory-standard-edition/ https://docs.aws.amazon.com/quicksight/latest/user/external-identity-providers.html

Here's the link if you need further assistance using Quicksight with IAM policies and roles: https://docs.aws.amazon.com/quicksight/latest/user/security_iam_service-with-iam.html

Josie_K
已回答 2 年前
0

Hello, I have the same concern, only what would happen if I have my quicksight configured by SSO and I want to enter the mobile application with IAM users or the quicksight console by IAM users without being redirected to SSO?

hcantos
已回答 1 年前
0

No you cannot configure a single QuickSight account to use both AD and IAM users. If you use AD it is all or nothing. If you use IAM you can federate users from multiple Identity Providers though (some internal some external for instance).

已回答 1 年前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则