QuestionQ44

Identity and Access Management

A company operates multiple accounts in the AWS Cloud. Users in the developer account require access to particular resources in the production account.

What is the MOST secure method to grant this access?

Explanation

An IAM role in the production account can be granted only the required permissions to production resources and configured to trust authorized principals from the developer account. Those principals assume the role to receive temporary, scoped credentials, avoiding shared passwords or long-term cross-account IAM-user credentials.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!