AWS IAM Identity Centerを特定組織にスモールスタート導入してみた - Qiita

目次 1. はじめに 2. 導入の経緯と構成の考え方 3. Identity Center 導入の流れ Step1. 管理部門への協力要請 Step2. AWS Organizations の「すべての機能」の有効化 Step3. Identity Center の...

Qiita

It could be said. Maybe. Possibly. That my hubris got in the way of my success, when I said I could migrate the organizations 200+ #AWS accounts & 150+ user accounts from #IAM to #IdentityCenter & #SSO in a single quarter without interruption. #infosec #security

Maybe.

Getting Around One of the AWS SSO (Identity Center) Weaknesses
~~
ACM.225 Designing AWS Identity Center Permission Sets and Policies
~~
by Teri Radichel | May 31,2023
#aws #identitycenter #sso #iam #session #compromise #attack #cloud #security

https://medium.com/cloud-security/getting-around-one-of-the-aws-sso-identity-center-weaknesses-d5f984497c29

AWS SSO (IAM Identity Center) for Separation of Duties: ACM.126 Creating a permission set for DNS Administrators in AWS SSO
~~~~~~~~~~~~
by Teri Radichel | Jan 8, 2023
#aws #identitycenter #sso #separationofduties #cybersecurity

https://medium.com/cloud-security/aws-sso-iam-identity-center-for-separation-of-duties-f9e6627fc5a3

AWS SSO (IAM Identity Center) for Separation of Duties

In my last post I explained how you can have better governance and control the risks associated with DNS configuration changes by segregating your domain names out to a separate account and only…

Cloud Security

@DMEdwards
Let me know when office hours are over 🙂

Is the "IAM Identity Center delegated administrator account" different from the "delegated admin account for AWS Account Management"?

I'm a fan of the aws-cli and documenting what I do for repeatability, so I'm trying to see if I can designate a delegated account in the CLI.

(Every minute I spend trying to figure out things like this is one minute closer to giving up trying to use Identity Center for the day.)

#aws #identitycenter