Skip to content

AWS Organizations: Determine what account to store user identies #15

Open
badra001 opened this issue Dec 14, 2021 · 0 comments
Open

AWS Organizations: Determine what account to store user identies #15

badra001 opened this issue Dec 14, 2021 · 0 comments
Labels
enhancement New feature or request

Comments

@badra001
Copy link
Contributor

We want to stop creating IAM user accounts all over the place, which leads to lots of access keys and rotation challenges.

To overcome this, we want a central account into which IAM accounts will be created with access keys, so there is one place to go for the access key. Then, access to all other iam stuff is via roles with cross account access.

Other possible solutions include AWS SSO, and this may be implemented in addition to a central account.

The question is, where in the OU does this belong? What other functions can/should this account have?

@badra001 badra001 added the enhancement New feature or request label Dec 14, 2021
Sign in to join this conversation on GitHub.
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant