SlideShare a Scribd company logo
1 of 22
Download to read offline
AWS Community
© 2023, Amazon Web Services, Inc. or its affiliates.
Secure from Day-0: Increase Your Security
Posture with Temporary Elevated Access and
AWS IAM Identity Center
Vladimir Cageyv Samoylov
AWS Community Builder – Thailand
AWS Community
© 2023, Amazon Web Services, Inc. or its affiliates.
Twitter / X
AWS Community
Key Takeaway
Role-based access control
IAM Identity Center
Temporary Elevated Access (just-in-time access)
AWS Community
© 2023, Amazon Web Services, Inc. or its affiliates.
Cross-account IAM Nightmare
AWS Community
First day is a new CISO
AWS Community
First day is a new CISO
AWS Community
© 2023, Amazon Web Services, Inc. or its affiliates.
Granting permissions. Role-based
access control.
AWS Community
- Developer Bob needs to get data from Production Database
- Bob asked his team lead Kate for permissions
- Kate told that company policy don’t allow access to Production Database and she have to ask CTO
- CTO was busy for a week and finally response that this is okay to grant Bob required permissions
and also change a policy and etc
- Kate asked InfraSec team to implement new security policy and grant Bob required permissions
- Bob finally able to get data from database and it allows him to implement new feature in the
codebase
How it usually happens?
AWS Community
- Time. Depends of the company size this process could takes from days to weeks.
- Maintenance. As company grows it will be more and more complex systems with many groups and
roles.
- Security. Our developer or developers will permanently have new permissions.
What problems do we see?
AWS Community
© 2023, Amazon Web Services, Inc. or its affiliates.
Temporary Elevated Access
AWS Community
Temporary elevated access (also known as just-in-time access) is a way to request, approve, and track
the use of a permission to perform a specific task during a specified time. Temporary elevated access
supplements other forms of access control, such as permission sets and multi-factor authentication.
Temporary Elevated Access
Approve Action
Request
More info: https://docs.aws.amazon.com/singlesignon/latest/userguide/temporary-elevated-
access.html
AWS Community
Another way of getting access
AWS Community
© 2023, Amazon Web Services, Inc. or its affiliates.
Sounds interesting. How could I do it in
my company?
AWS Community
AWS Organizations
More info: https://aws.amazon.com/organizations/
AWS Community
AWS IAM Identity Center (AWS Single Sign-On)
More info: https://aws.amazon.com/iam/identity-center/
AWS Community
Validated AWS Security Partners for temporary
elevated access
More info: https://docs.aws.amazon.com/singlesignon/latest/userguide/temporary-elevated-
access.html#validatedpartners
AWS Community
Temporary elevated access management
(TEAM)
More info: https://aws-samples.github.io/iam-identity-center-team/
AWS Community
© 2023, Amazon Web Services, Inc. or its affiliates.
terraform-aws-sso-elevator
AWS Community
SSO-Elevator
More info: https://github.com/fivexl/terraform-aws-sso-elevator
AWS Community
SSO-Elevator (demo)
More info: https://youtu.be/iR3Rdjd7QMU
AWS Community
AWS Community
© 2023, Amazon Web Services, Inc. or its affiliates.
https://www.awscommunity.dev
22
Thank you
Go to link below for submitting your content request:
https://go.awscommunity.dev/request

More Related Content

Similar to Increase Your Security Posture with Temporary Elevated Access and AWS IAM Identity Center

Azure from scratch part 2 By Girish Kalamati
Azure from scratch part 2 By Girish KalamatiAzure from scratch part 2 By Girish Kalamati
Azure from scratch part 2 By Girish Kalamati
Girish Kalamati
 
AWS Basic Practitioner Heena Talreja.pptx
AWS Basic Practitioner Heena Talreja.pptxAWS Basic Practitioner Heena Talreja.pptx
AWS Basic Practitioner Heena Talreja.pptx
Hitendrasingh79
 
Design for Compliance - AWS FS Cloud Symposium Apr 2019.pdf
Design for Compliance - AWS FS Cloud Symposium Apr 2019.pdfDesign for Compliance - AWS FS Cloud Symposium Apr 2019.pdf
Design for Compliance - AWS FS Cloud Symposium Apr 2019.pdf
Amazon Web Services
 
What's New in AWS Security Features
What's New in AWS Security FeaturesWhat's New in AWS Security Features
What's New in AWS Security Features
Amazon Web Services
 

Similar to Increase Your Security Posture with Temporary Elevated Access and AWS IAM Identity Center (20)

Scale permissions management in AWS with attribute-based access control - SDD...
Scale permissions management in AWS with attribute-based access control - SDD...Scale permissions management in AWS with attribute-based access control - SDD...
Scale permissions management in AWS with attribute-based access control - SDD...
 
AWS Partner Webcast - Get Closer to the Cloud with Federated Single Sign-On
AWS Partner Webcast - Get Closer to the Cloud with Federated Single Sign-OnAWS Partner Webcast - Get Closer to the Cloud with Federated Single Sign-On
AWS Partner Webcast - Get Closer to the Cloud with Federated Single Sign-On
 
AWS Certified Solutions Architect Professional Course S1-S5
AWS Certified Solutions Architect Professional Course S1-S5AWS Certified Solutions Architect Professional Course S1-S5
AWS Certified Solutions Architect Professional Course S1-S5
 
Evolving perimeters with guardrails, not gates: Improving developer agility -...
Evolving perimeters with guardrails, not gates: Improving developer agility -...Evolving perimeters with guardrails, not gates: Improving developer agility -...
Evolving perimeters with guardrails, not gates: Improving developer agility -...
 
Getting Started with AWS Security
Getting Started with AWS SecurityGetting Started with AWS Security
Getting Started with AWS Security
 
Become an IAM Policy Master in 60 Minutes or Less (SEC316-R1) - AWS reInvent ...
Become an IAM Policy Master in 60 Minutes or Less (SEC316-R1) - AWS reInvent ...Become an IAM Policy Master in 60 Minutes or Less (SEC316-R1) - AWS reInvent ...
Become an IAM Policy Master in 60 Minutes or Less (SEC316-R1) - AWS reInvent ...
 
Identity and o365 on Azure
Identity and o365 on AzureIdentity and o365 on Azure
Identity and o365 on Azure
 
Azure from scratch part 2 By Girish Kalamati
Azure from scratch part 2 By Girish KalamatiAzure from scratch part 2 By Girish Kalamati
Azure from scratch part 2 By Girish Kalamati
 
AWS Basic Practitioner Heena Talreja.pptx
AWS Basic Practitioner Heena Talreja.pptxAWS Basic Practitioner Heena Talreja.pptx
AWS Basic Practitioner Heena Talreja.pptx
 
Design for Compliance - AWS FS Cloud Symposium Apr 2019.pdf
Design for Compliance - AWS FS Cloud Symposium Apr 2019.pdfDesign for Compliance - AWS FS Cloud Symposium Apr 2019.pdf
Design for Compliance - AWS FS Cloud Symposium Apr 2019.pdf
 
The 1%: Identity and Governance Patterns from the Most Advanced AWS Customers...
The 1%: Identity and Governance Patterns from the Most Advanced AWS Customers...The 1%: Identity and Governance Patterns from the Most Advanced AWS Customers...
The 1%: Identity and Governance Patterns from the Most Advanced AWS Customers...
 
AWS IAM Introduction
AWS IAM IntroductionAWS IAM Introduction
AWS IAM Introduction
 
What's New in AWS Security Features
What's New in AWS Security FeaturesWhat's New in AWS Security Features
What's New in AWS Security Features
 
AZ-500-Questions.pdf
AZ-500-Questions.pdfAZ-500-Questions.pdf
AZ-500-Questions.pdf
 
Jeff Lombardo - Enforcing access control in depth with AWS - v1.2.pdf
Jeff Lombardo - Enforcing access control in depth with AWS - v1.2.pdfJeff Lombardo - Enforcing access control in depth with AWS - v1.2.pdf
Jeff Lombardo - Enforcing access control in depth with AWS - v1.2.pdf
 
The 1% Identity and Governance Patterns from the Most Advanced AWS Customers ...
The 1% Identity and Governance Patterns from the Most Advanced AWS Customers ...The 1% Identity and Governance Patterns from the Most Advanced AWS Customers ...
The 1% Identity and Governance Patterns from the Most Advanced AWS Customers ...
 
Best practices for choosing identity solutions for applications + workloads -...
Best practices for choosing identity solutions for applications + workloads -...Best practices for choosing identity solutions for applications + workloads -...
Best practices for choosing identity solutions for applications + workloads -...
 
AWS Webcast - AWS Compliance Forum Introduction Oct 2013
AWS Webcast - AWS Compliance Forum Introduction Oct 2013AWS Webcast - AWS Compliance Forum Introduction Oct 2013
AWS Webcast - AWS Compliance Forum Introduction Oct 2013
 
Pitt Immersion Day Module 5 - security overview
Pitt Immersion Day Module 5 - security overviewPitt Immersion Day Module 5 - security overview
Pitt Immersion Day Module 5 - security overview
 
IAM for Enterprises: How Vanguard Matured IAM Controls to Support Micro Accou...
IAM for Enterprises: How Vanguard Matured IAM Controls to Support Micro Accou...IAM for Enterprises: How Vanguard Matured IAM Controls to Support Micro Accou...
IAM for Enterprises: How Vanguard Matured IAM Controls to Support Micro Accou...
 

Recently uploaded

Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...
Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...
Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...
David Celestin
 
Jual obat aborsi Jakarta 085657271886 Cytote pil telat bulan penggugur kandun...
Jual obat aborsi Jakarta 085657271886 Cytote pil telat bulan penggugur kandun...Jual obat aborsi Jakarta 085657271886 Cytote pil telat bulan penggugur kandun...
Jual obat aborsi Jakarta 085657271886 Cytote pil telat bulan penggugur kandun...
ZurliaSoop
 
Unlocking Exploration: Self-Motivated Agents Thrive on Memory-Driven Curiosity
Unlocking Exploration: Self-Motivated Agents Thrive on Memory-Driven CuriosityUnlocking Exploration: Self-Motivated Agents Thrive on Memory-Driven Curiosity
Unlocking Exploration: Self-Motivated Agents Thrive on Memory-Driven Curiosity
Hung Le
 

Recently uploaded (19)

ECOLOGY OF FISHES.pptx full presentation
ECOLOGY OF FISHES.pptx full presentationECOLOGY OF FISHES.pptx full presentation
ECOLOGY OF FISHES.pptx full presentation
 
SOLID WASTE MANAGEMENT SYSTEM OF FENI PAURASHAVA, BANGLADESH.pdf
SOLID WASTE MANAGEMENT SYSTEM OF FENI PAURASHAVA, BANGLADESH.pdfSOLID WASTE MANAGEMENT SYSTEM OF FENI PAURASHAVA, BANGLADESH.pdf
SOLID WASTE MANAGEMENT SYSTEM OF FENI PAURASHAVA, BANGLADESH.pdf
 
Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...
Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...
Proofreading- Basics to Artificial Intelligence Integration - Presentation:Sl...
 
Jual obat aborsi Jakarta 085657271886 Cytote pil telat bulan penggugur kandun...
Jual obat aborsi Jakarta 085657271886 Cytote pil telat bulan penggugur kandun...Jual obat aborsi Jakarta 085657271886 Cytote pil telat bulan penggugur kandun...
Jual obat aborsi Jakarta 085657271886 Cytote pil telat bulan penggugur kandun...
 
Using AI to boost productivity for developers
Using AI to boost productivity for developersUsing AI to boost productivity for developers
Using AI to boost productivity for developers
 
BIG DEVELOPMENTS IN LESOTHO(DAMS & MINES
BIG DEVELOPMENTS IN LESOTHO(DAMS & MINESBIG DEVELOPMENTS IN LESOTHO(DAMS & MINES
BIG DEVELOPMENTS IN LESOTHO(DAMS & MINES
 
Introduction to Artificial intelligence.
Introduction to Artificial intelligence.Introduction to Artificial intelligence.
Introduction to Artificial intelligence.
 
Abortion Pills Fahaheel ௹+918133066128💬@ Safe and Effective Mifepristion and ...
Abortion Pills Fahaheel ௹+918133066128💬@ Safe and Effective Mifepristion and ...Abortion Pills Fahaheel ௹+918133066128💬@ Safe and Effective Mifepristion and ...
Abortion Pills Fahaheel ௹+918133066128💬@ Safe and Effective Mifepristion and ...
 
LITTLE ABOUT LESOTHO FROM THE TIME MOSHOESHOE THE FIRST WAS BORN
LITTLE ABOUT LESOTHO FROM THE TIME MOSHOESHOE THE FIRST WAS BORNLITTLE ABOUT LESOTHO FROM THE TIME MOSHOESHOE THE FIRST WAS BORN
LITTLE ABOUT LESOTHO FROM THE TIME MOSHOESHOE THE FIRST WAS BORN
 
in kuwait௹+918133066128....) @abortion pills for sale in Kuwait City
in kuwait௹+918133066128....) @abortion pills for sale in Kuwait Cityin kuwait௹+918133066128....) @abortion pills for sale in Kuwait City
in kuwait௹+918133066128....) @abortion pills for sale in Kuwait City
 
Digital collaboration with Microsoft 365 as extension of Drupal
Digital collaboration with Microsoft 365 as extension of DrupalDigital collaboration with Microsoft 365 as extension of Drupal
Digital collaboration with Microsoft 365 as extension of Drupal
 
ICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdfICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdf
 
"I hear you": Moving beyond empathy in UXR
"I hear you": Moving beyond empathy in UXR"I hear you": Moving beyond empathy in UXR
"I hear you": Moving beyond empathy in UXR
 
History of Morena Moshoeshoe birth death
History of Morena Moshoeshoe birth deathHistory of Morena Moshoeshoe birth death
History of Morena Moshoeshoe birth death
 
BEAUTIFUL PLACES TO VISIT IN LESOTHO.pptx
BEAUTIFUL PLACES TO VISIT IN LESOTHO.pptxBEAUTIFUL PLACES TO VISIT IN LESOTHO.pptx
BEAUTIFUL PLACES TO VISIT IN LESOTHO.pptx
 
2024 mega trends for the digital workplace - FINAL.pdf
2024 mega trends for the digital workplace - FINAL.pdf2024 mega trends for the digital workplace - FINAL.pdf
2024 mega trends for the digital workplace - FINAL.pdf
 
Unlocking Exploration: Self-Motivated Agents Thrive on Memory-Driven Curiosity
Unlocking Exploration: Self-Motivated Agents Thrive on Memory-Driven CuriosityUnlocking Exploration: Self-Motivated Agents Thrive on Memory-Driven Curiosity
Unlocking Exploration: Self-Motivated Agents Thrive on Memory-Driven Curiosity
 
Ready Set Go Children Sermon about Mark 16:15-20
Ready Set Go Children Sermon about Mark 16:15-20Ready Set Go Children Sermon about Mark 16:15-20
Ready Set Go Children Sermon about Mark 16:15-20
 
The Concession of Asaba International Airport: Balancing Politics and Policy ...
The Concession of Asaba International Airport: Balancing Politics and Policy ...The Concession of Asaba International Airport: Balancing Politics and Policy ...
The Concession of Asaba International Airport: Balancing Politics and Policy ...
 

Increase Your Security Posture with Temporary Elevated Access and AWS IAM Identity Center

  • 1. AWS Community © 2023, Amazon Web Services, Inc. or its affiliates. Secure from Day-0: Increase Your Security Posture with Temporary Elevated Access and AWS IAM Identity Center Vladimir Cageyv Samoylov AWS Community Builder – Thailand
  • 2. AWS Community © 2023, Amazon Web Services, Inc. or its affiliates. Twitter / X
  • 3. AWS Community Key Takeaway Role-based access control IAM Identity Center Temporary Elevated Access (just-in-time access)
  • 4. AWS Community © 2023, Amazon Web Services, Inc. or its affiliates. Cross-account IAM Nightmare
  • 5. AWS Community First day is a new CISO
  • 6. AWS Community First day is a new CISO
  • 7. AWS Community © 2023, Amazon Web Services, Inc. or its affiliates. Granting permissions. Role-based access control.
  • 8. AWS Community - Developer Bob needs to get data from Production Database - Bob asked his team lead Kate for permissions - Kate told that company policy don’t allow access to Production Database and she have to ask CTO - CTO was busy for a week and finally response that this is okay to grant Bob required permissions and also change a policy and etc - Kate asked InfraSec team to implement new security policy and grant Bob required permissions - Bob finally able to get data from database and it allows him to implement new feature in the codebase How it usually happens?
  • 9. AWS Community - Time. Depends of the company size this process could takes from days to weeks. - Maintenance. As company grows it will be more and more complex systems with many groups and roles. - Security. Our developer or developers will permanently have new permissions. What problems do we see?
  • 10. AWS Community © 2023, Amazon Web Services, Inc. or its affiliates. Temporary Elevated Access
  • 11. AWS Community Temporary elevated access (also known as just-in-time access) is a way to request, approve, and track the use of a permission to perform a specific task during a specified time. Temporary elevated access supplements other forms of access control, such as permission sets and multi-factor authentication. Temporary Elevated Access Approve Action Request More info: https://docs.aws.amazon.com/singlesignon/latest/userguide/temporary-elevated- access.html
  • 12. AWS Community Another way of getting access
  • 13. AWS Community © 2023, Amazon Web Services, Inc. or its affiliates. Sounds interesting. How could I do it in my company?
  • 14. AWS Community AWS Organizations More info: https://aws.amazon.com/organizations/
  • 15. AWS Community AWS IAM Identity Center (AWS Single Sign-On) More info: https://aws.amazon.com/iam/identity-center/
  • 16. AWS Community Validated AWS Security Partners for temporary elevated access More info: https://docs.aws.amazon.com/singlesignon/latest/userguide/temporary-elevated- access.html#validatedpartners
  • 17. AWS Community Temporary elevated access management (TEAM) More info: https://aws-samples.github.io/iam-identity-center-team/
  • 18. AWS Community © 2023, Amazon Web Services, Inc. or its affiliates. terraform-aws-sso-elevator
  • 19. AWS Community SSO-Elevator More info: https://github.com/fivexl/terraform-aws-sso-elevator
  • 20. AWS Community SSO-Elevator (demo) More info: https://youtu.be/iR3Rdjd7QMU
  • 22. AWS Community © 2023, Amazon Web Services, Inc. or its affiliates. https://www.awscommunity.dev 22 Thank you Go to link below for submitting your content request: https://go.awscommunity.dev/request