QuestionQ10
Security and ComplianceA company has multiple AWS accounts and uses AWS Single Sign-On (AWS SSO), integrated with AWS Toolkit for Microsoft Azure DevOps. The attributes-for-access-control feature is enabled in AWS SSO.
The attribute mapping list contains two entries. The department key maps to $\{path:enterprise.department\}. The costCenter key maps to $\{path:enterprise.costCenter\}.
All existing Amazon EC2 instances have a department tag corresponding to three company departments (d1, d2, d3). A DevOps engineer must create policies based on matching attributes. The policies must minimize administrative effort and grant each Azure AD user access only to EC2 instances tagged with that user's department name.
Which condition key should the DevOps engineer include in the custom permissions policies to meet these requirements?
Community Discussion