Broadcast Date: March 27, 2019

Level: 300

In this tech talk, we will share best practices to manage permissions at scale for these workloads. We start by recommending ways you can separate workloads using accounts and AWS Organizations. Once you have an account structure that scales with your business needs, we share preventative guardrails you can enable across your AWS organization. This helps you ensure that rules of your organization are followed consistently across your workloads. With permission guardrails in place, we shift focus to granting permissions within an account. We review how you can enable developers to create Identity and Access Management (IAM) roles for the applications using permission boundaries. We also review how to develop permission rules that set granular permissions that scale as you add resources using attribute-based access control. With guardrails and scalable permissions, we show you how you can grant developers broad access enabling them to move fast building on AWS, while monitoring and reducing permissions using IAM access advisor as their access patterns settle.

Learning Objectives

  • Understand AWS capabilities to quickly setup a manageable account structure to suit your needs
  • Learn how to set permissions guardrails and maintain consistency across your organization
  • Learn how to delegate permissions management to developers in a controlled and scalable manner

Who Should Attend?

Security Admins, IAM Admins, AWS Administrators, AWS Users

Speakers

  • Brigid Johnson, Sr. Manager, Product Management, AWS


Learn More

To learn more about the services featured in this talk, please visit:
https://aws.amazon.com/iam

Intro body copy here about 2018 re:Invent launches.

Download the Slide Deck

Compute

Service How To

December 19th, 2018 | 1:00 PM PT

Developing Deep Learning Models for Computer Vision with
Amazon EC2 P3 Instances.

Register Now>

Containers

What's New / Cloud Innovation

December 11th, 2018 | 1:00 PM PT

EMBARGOED

Register Now>

Data Lakes & Analytics

Webinar 1:

What's New / Cloud Innovation

December 10th, 2018 | 11:00 AM PT

EMBARGOED

Register Now>

Webinar 2:

What's New / Cloud Innovation

December 12th, 2018 | 11:00 AM PT

EMBARGOED

Register Now>