A security auditor needs to gain read-only access to all AWS accounts within an AWS Organization to review security configurations and compliance. The auditor's team uses a dedicated audit AWS account. The solution must ensure that the auditor's access is restricted to read-only operations and that the access can be easily revoked centrally if needed. Which approach should be implemented?
- ASet up AWS SSO (IAM Identity Center) to provision a read-only permission set for the auditor's group, assigned to all organizational units (OUs).
- BCreate an IAM user in each member account with a read-only policy and share the credentials with the auditor.
- CConfigure cross-account role assumption from the audit account to a 'SecurityAudit' role in each member account, with a read-only policy attached to the role.
- DImplement AWS Organizations Service Control Policies (SCPs) to grant read-only access to the auditor's IAM user across all accounts.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure cross-account role assumption from the audit account to a 'SecurityAudit' role in each member account, with a read-only policy attached to the role.
Cross-account role assumption is the standard and most secure way to grant access to multiple accounts from a central account. By defining a 'SecurityAudit' role with a read-only policy in each member account and configuring a trust policy to allow the audit account to assume it, centralized management and easy revocation are achieved. SCPs are preventive guardrails, not identity-based access grants.
Why the other options are wrong
- A. While IAM Identity Center (formerly AWS SSO) could simplify user access, the prompt specifies an auditor's team in a dedicated audit account, implying programmatically or role-based access for auditing tools. Even with IAM Identity Center, the underlying mechanism for cross-account access to AWS resources often involves roles. The direct role assumption is a more foundational and direct answer to the 'read-only access to all AWS accounts' requirement without introducing the full SSO infrastructure if not explicitly needed.
- B. Creating IAM users in each account is not scalable, difficult to manage, and sharing credentials is a security risk. Revocation would also be complex.
- D. SCPs are preventive guardrails that set maximum permissions for IAM entities in member accounts; they do not grant access directly. An SCP cannot grant read-only access to a specific IAM user across accounts.
Cross-Account Role Assumption
An AWS IAM mechanism allowing an IAM principal in one AWS account to temporarily assume an IAM role in another AWS account, gaining the permissions defined by that role.
- Uses an IAM role with a trust policy that specifies the trusted account.
- The principal in the trusted account performs an 'AssumeRole' API call.
- Provides temporary credentials for the assumed role.
- Ideal for centralized management of access across multiple accounts.
Memory trick: Roles are the bridge, for accounts toidge (interact).