Create an administrator-like profile/role outside the management account

0

I have multiple accounts in Organizations and wanted a way to manage them securely. I want to create a user or give my user permission as if they were an administrator (in this multiple accounts), so I don't have to use the management account. What's the best way to do this?

I saw that I can use permission boundaries, but I didn't find examples of how it would be applied to an administrator-like user or how I can write a policy and permission boundaries in this case for an administrator. Besides that, would any other action be recommended? Any blockage on the management account? Thanks!

natte
已提問 7 個月前檢視次數 195 次
2 個答案
1

Hello.

If you are using Organizations, you can use SCP to restrict operations.
You might be able to accomplish what you want using this.
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html

profile picture
專家
已回答 7 個月前
0

You might want to also check out delegated administration. Delegated administration provides a convenient way for assigned users in a registered member account to perform most IAM Identity Center administrative tasks. More here: https://docs.aws.amazon.com/singlesignon/latest/userguide/delegated-admin.html

profile pictureAWS
已回答 6 個月前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南