I still can't get why the same IAM role and its policies provisioned in ALL accounts is considered secure? Do all your devs have the same access in prod and non-prod environments?
@awssupport6 ай бұрын
Hi there. For assistance with your query, you're welcome to reach out via our re:Post community of experts, here: go.aws/aws-repost. ^AM
@AndersonCarvalho-m7m5 ай бұрын
The the role entitlement do the mapping between account/group/permissionSet. The roles are only provisioned in the accounts where the role entitlement exists. The idea of reducing the number of permission sets is to simplify management and the creation of "roles" that follows the least previledge principle and the idea of the automation is allow the Identity Admin to grant access to accounts based on a giving role without needing to go to AWS.