AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium

A company uses AWS SSO (IAM Identity Center) to manage access to multiple AWS accounts. They have several AWS accounts organized into Organizational Units (OUs). A new security policy requires that all users in the 'Developers' group, who are part of the 'Development' OU, must have read-only access to all S3 buckets in their respective development accounts. How should this be configured using IAM Identity Center?

  1. AAttach an inline policy to each 'Developers' IAM user in each development account with S3 read-only permissions.
  2. BImplement a Service Control Policy (SCP) in the 'Development' OU to grant S3 read-only access to the 'Developers' group.
  3. CDefine a permission set with S3 read-only access and assign it to the 'Developers' group for the 'Development' OU.
  4. DCreate an IAM role with S3 read-only permissions in each development account and manually assign it to the 'Developers' group.
Show answer & explanation

Correct answer: C. Define a permission set with S3 read-only access and assign it to the 'Developers' group for the 'Development' OU.

IAM Identity Center uses permission sets to define access to AWS accounts. By creating a permission set with S3 read-only access and assigning it to the 'Developers' group for the 'Development' OU, access is centrally managed and automatically provisioned to all accounts within that OU for the specified group.

Why the other options are wrong

  • A. IAM Identity Center manages access centrally, avoiding the need to create and manage IAM users or inline policies directly in each AWS account. This option defeats the purpose of using IAM Identity Center for centralized management.
  • B. SCPs are guardrails that set maximum permissions; they do not grant access. An SCP cannot be used to grant S3 read-only access to a specific group.
  • D. While creating IAM roles is part of the underlying process, IAM Identity Center automates the creation and management of these roles via permission sets, making manual creation and assignment inefficient and not leveraging the benefits of IAM Identity Center.

IAM Identity Center Permission Sets

A collection of administrative policies that define a user's access to an AWS account, managed centrally by IAM Identity Center.

  • Defines permissions for users/groups to access AWS accounts.
  • Applied to groups and assigned to specific accounts or OUs.
  • IAM Identity Center automatically provisions corresponding IAM roles in target accounts.
  • Simplifies access management across multiple AWS accounts.

Memory trick: Permission Sets are the key to groups' access, across accounts with grace.

More Domain 4: Identity and Access Management questions