QuestionQ51

Identity and Access Management

A company that uses AWS Organizations uses AWS IAM Identity Center (AWS Single Sign-On) to manage access to AWS accounts. A security engineer is creating a custom permission set in IAM Identity Center. The company will use this permission set across multiple accounts. An AWS managed policy and a customer managed policy are attached to the permission set. The security engineer has full administrative permissions and is working in the management account.

When the security engineer tries to assign the permission set to an IAM Identity Center user with access to multiple accounts, the assignment fails.

What should the security engineer do to resolve this failure?

Explanation

IAM Identity Center requires a customer managed policy referenced by a permission set to exist in every AWS account where that permission set is assigned, with the same policy name and path. Creating matching customer managed policies in all target accounts allows IAM Identity Center to provision the assignment successfully; AWS managed policies are already available in AWS accounts.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!