SlideShare uma empresa Scribd logo
1 de 25
Pop-up Loft
Overview of AWS Identity, Directory, and Access Services
Ron Cully
Manager, Directory Service Product Management
Amazon Web Services
Every AWS Cloud journey is unique.
Migrating or extending
existing infrastructure
and applications.
Building customer
facing cloud-native
applications.
Going all-in on cloud
solutions across the
organization.
Using the scale of the
AWS Cloud to solve new
challenges.
Requiring unique identity and
access management solutions.
What to Expect
(C) Copyright Jean-Remy Duboc and licensed for reuse under the
Creative Commons Attribution-Generic 2.0 License
Provide
mental model
Chart the
Cloudscape
How to Use
IDAS Services
Disambiguation
Identity and Access Mgmt
(the subject)
AWS IAM
(the service)
Authentication,
authorization, audit and
governance for your cloud
workloads
Our scope
Authenticates and
authorizes AWS APIs
Includes
Identity and Access Management means…
Validate identities
securely
Authentication
Manage access using
fine-grained policies
Authorization
Meet compliance
requirements
Audit/Governance
At all levels…
Identity and Access Management
(the subject)
AWS Management Console/APIs
AWS
Infrastructure
AWS
Applications
Your Applications
Developers
Admins
Security Employees
Customers
Partners
Tenets
Mental model for Identity and Access Management services
Give you choice Secure, flexible,
comprehensive
Meet you
where you are
Benefits of AWS Identity, Directory,
and Access Services
Superior Security
Enable you to build applications and manage access more
securely in the AWS Cloud than on premises.
Increase Flexibility
Offer you options that meet you along your AWS Cloud
journey instead of forcing you to adapt to AWS.
Comprehensive
Breadth of services that help you get started quickly and are
feature rich to meet your more advanced needs over time.
Landscape
AWS Identity, Directory,
and Access Services
AWS Secrets Manager
(NEW!)
Lifecycle management
for application secrets.
AWS Identity and
Access Management
Fine-grained access
management for AWS
resources.
AWS
Organizations
Policy-based
management for
multiple AWS accounts.
AWS Directory Service
Integrates Active
Directory in AWS for
Windows workloads,
AWS resource access,
and AWS
AWS Single Sign-On
Manage single sign-on
(SSO) access to
multiple AWS accounts
and business
applications.
Broader Security Portfolio
AWS Config Rules
AWS Lambda
Incident
response
AWS Identity & Access
Management (IAM)
AWS Organizations
AWS Cognito
AWS Single Sign-On
AWS Directory Service
AWS Secrets Manager
Identity
AWS CloudTrail
AWS Config
Amazon
CloudWatch
Amazon GuardDuty
VPC Flow Logs
Detective
control
Amazon EC2
Systems Manager
AWS Shield
AWS Web Application
Firewall (WAF)
Amazon Inspector
Amazon Virtual Private
Cloud (VPC)
Infrastructure
security
AWS Key Management
Service (KMS)
AWS CloudHSM
Amazon Macie
Certificate Manager
Server Side Encryption
Data
protection
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Accounts
Account
Account
Account
Account Account
Account
Account
Account Account
Account
Account
AccountAccount
Account
Account
AWS Resources
AWS Organizations
M
Master Account / Administrative root
A1 A2 A4 AWS AccountsA3
Organizational Unit (OU)Dev Test Prod
Service
Control
Policies
(SCPs)
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
SaaS
App
Account
IdP
SAML
OIDC
Federated
Users
Applications
IAM
Group
IAM Users
Security Principals
R
Root
Identity-based
Policies
EBS EC2
Resource-based
Policies
S3 SNS
ECR KMS
SES CognitoOrganizations RDS CloudWatch
AD
DS
AWS IAM
Service Control
Policies
Resulting
Permissions
Resource-based
Policies
Identity-based
Policies
Roles
Old
School
What’s my
permission?
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
IAM
Group
IAM Users Federated
Users
Roles Applications
R
Root
Identity-based
Policies
AWS IAM
How to Use IDAS Services
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Roles
Identity-based
Policies
R
Root
IAM Users
IAM
Group
Federated
Users
Applications
Assign permission to assume
roles and apply policies to roles
Use root to set up initial
admin users only
Require strong passwords for
users
ALWAYS set up multi-factor
authentication for Root user
and ideally for all other users
Don’t embed secrets in code!
Use AWS Secrets Manager
AWS IAM: Best Practices
*************
*************
// Authenticate app
User = “App1”
Pwd = “App1Pwd”
1X
Old
School
Lifecycle management for secrets such as
database credentials and API keys.
Rotate Secrets
Safely
Pay as you goManage access
with fine-grained
policies
Secure and
audit secrets
centrally
AWS Secrets Manager
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
User Identity Strategy
IdP
SAML
OIDC
Federated
Users
Have an existing
SAML or OIDC
infrastructure
Don’t need/want
Active Directory
in the AWS Cloud
IAM
Group
IAM Users
Small team, don’t
have a directory
Have or need
Active Directory
for users and groups
AD
Federated
Users
DS
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
AWS Managed AD: User Forest
Enable, authenticate, &
authorize
.NET
Applications
Server
SharePoint
Server
AD-aware Workloads
SQL ServerRemote
Desktop
Licensing
Manager
.NET SharePoint
SQL
Server
RD
Licensing
Enterprise
Certificate
Authority
Certificate
Services
SaaS Applications
Azure AD
Amazon
WorkSpaces
Amazon
WorkDocs
Amazon
WorkMail
Amazon
QuickSight
AWS Management
Console
Amazon
Chime
Amazon
Connect
AWS Apps & Services
RDS for SQL
Server
AWS Managed
Microsoft AD
SAML
authenticate
Synchronize
users
AD FS
Server
AD FS
Azure AD
Connect
Server
Federate
ADSync
Manage, authenticate,
& authorize
Domain Join & Manage
Amazon EC2
Amazon
Windows EC2
instances
Amazon Linux
EC2 Instances
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
AWS Managed AD: User Forest
Enable, authenticate, &
authorize
.NET
Applications
Server
SharePoint
Server
AD-aware Workloads
SQL ServerRemote
Desktop
Licensing
Manager
.NET SharePoint
SQL
Server
RD
Licensing
Enterprise
Certificate
Authority
Certificate
Services
SaaS Applications
Azure AD
Amazon
WorkSpaces
Amazon
WorkDocs
Amazon
WorkMail
Amazon
QuickSight
AWS Management
Console
Amazon
Chime
Amazon
Connect
AWS Apps & Services
RDS for SQL
Server
AWS Managed
Microsoft AD
Manage, authenticate,
& authorize
Domain Join & Manage
Amazon EC2
Amazon
Windows EC2
instances
Amazon Linux
EC2 Instances
On-premises
Microsoft Active
Directory
On-premises user
credentials
Corporate
data center
AD FS
Server
SAML
authenticate
Synchronize
users
Azure AD
Connect
Server
VPN
Direct
Connect
or
Trust
Authenticate
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Federation with AD Connector
AD Connector
SaaS Applications
Azure AD
Domain Join & Manage
On-premises
Microsoft Active
Directory
On-premises user
credentials
Corporate
data centerVPN
Direct
Connect
or
AD FS
Server
SAML
authenticate
Synchronize
users
Azure AD
Connect
Server
Authenticate & Proxy LDAP
Provision & Authenticate
.NET
Applications
Server
SharePoint
Server
SQL ServerRemote
Desktop
Licensing
Manager
Enterprise
Certificate
Authority
AD-aware Workloads
.NET SharePoint
SQL
Server
RD
Licensing
Certificate
Services
Amazon EC2
Amazon
Windows EC2
instances
Amazon Linux
EC2 Instances
Amazon
WorkSpaces
Amazon
WorkDocs
Amazon
WorkMail
Amazon
QuickSight
AWS Management
Console
Amazon
Chime
Amazon
Connect
AWS Apps & Services
RDS for SQL
Server
AWS Single Sign-On
Entitlements
AWS SSO
Master Account
AWS Directory
Service
Groups
Active
Directory
On-premises
Install AWS SSO and
map AD groups
to defined permissions
Grant access to one AWS
account, an OU, or the
entire Organization
Connect AWS Directory
Service to on-premises AD
AWS Organizations
Account
SAML or OIDC Federation
SaaS Applications
Azure AD
On-premises
Microsoft Active
Directory
On-premises user
credentials
Corporate
data center
AD FS
Server
SAML
authenticate
Synchronize
users
Azure AD
Connect
Server
Account
Account
AWS IAM End-point for
Single Sign-on
Pop-up Loft
Questions?
Pop-up Loft
aws.amazon.com/activate
Everything and Anything Startups
Need to Get Started on AWS

Mais conteúdo relacionado

Mais procurados

AWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best Practices
Amazon Web Services
 
Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...
Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...
Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...
Amazon Web Services
 
Protect your applications from DDoS/BOT & Advanced Attacks
Protect your applications from DDoS/BOT & Advanced AttacksProtect your applications from DDoS/BOT & Advanced Attacks
Protect your applications from DDoS/BOT & Advanced Attacks
Amazon Web Services
 
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 

Mais procurados (20)

API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
AWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best Practices
 
An Amazonian Approach To Enterprise Transformation
An Amazonian Approach To Enterprise TransformationAn Amazonian Approach To Enterprise Transformation
An Amazonian Approach To Enterprise Transformation
 
Architecting for Enterprise Identity Across Multiple Operating Models (ENT413...
Architecting for Enterprise Identity Across Multiple Operating Models (ENT413...Architecting for Enterprise Identity Across Multiple Operating Models (ENT413...
Architecting for Enterprise Identity Across Multiple Operating Models (ENT413...
 
Transforming your Business Ops Team for Cloud - AWS Summit Sydney 2018
Transforming your Business Ops Team for Cloud - AWS Summit Sydney 2018Transforming your Business Ops Team for Cloud - AWS Summit Sydney 2018
Transforming your Business Ops Team for Cloud - AWS Summit Sydney 2018
 
Landing Zones - Creating a Foundation for Your AWS Migrations
Landing Zones - Creating a Foundation for Your AWS MigrationsLanding Zones - Creating a Foundation for Your AWS Migrations
Landing Zones - Creating a Foundation for Your AWS Migrations
 
Enterprise workloads on AWS
Enterprise workloads on AWSEnterprise workloads on AWS
Enterprise workloads on AWS
 
Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...
Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...
Accelerare l’utilizzo del Machine Learning con le soluzioni ML pronte per l’u...
 
Protect your applications from DDoS/BOT & Advanced Attacks
Protect your applications from DDoS/BOT & Advanced AttacksProtect your applications from DDoS/BOT & Advanced Attacks
Protect your applications from DDoS/BOT & Advanced Attacks
 
Microsoft Active Directory Deep Dive
Microsoft Active Directory Deep DiveMicrosoft Active Directory Deep Dive
Microsoft Active Directory Deep Dive
 
AWSome Day Online 2020_โมดูล 4: การรักษาความปลอดภัยแอปพลิเคชันบนระบบคลาวด์ของคุณ
AWSome Day Online 2020_โมดูล 4: การรักษาความปลอดภัยแอปพลิเคชันบนระบบคลาวด์ของคุณAWSome Day Online 2020_โมดูล 4: การรักษาความปลอดภัยแอปพลิเคชันบนระบบคลาวด์ของคุณ
AWSome Day Online 2020_โมดูล 4: การรักษาความปลอดภัยแอปพลิเคชันบนระบบคลาวด์ของคุณ
 
Transforming Enterprise IT - Virtual Transformation Day Feb 2019
Transforming Enterprise IT - Virtual Transformation Day Feb 2019Transforming Enterprise IT - Virtual Transformation Day Feb 2019
Transforming Enterprise IT - Virtual Transformation Day Feb 2019
 
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
 
Building a Hybrid Cloud Architecture Utilizing AWS Landing Zones
Building a Hybrid Cloud Architecture Utilizing AWS Landing ZonesBuilding a Hybrid Cloud Architecture Utilizing AWS Landing Zones
Building a Hybrid Cloud Architecture Utilizing AWS Landing Zones
 
Big Data Meets AI - Driving Insights and Adding Intelligence to Your Solutions
 Big Data Meets AI - Driving Insights and Adding Intelligence to Your Solutions Big Data Meets AI - Driving Insights and Adding Intelligence to Your Solutions
Big Data Meets AI - Driving Insights and Adding Intelligence to Your Solutions
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
 
AWS Security Hub
AWS Security HubAWS Security Hub
AWS Security Hub
 
Mission (Not) Impossible: Applying NIST 800-53 High Impact-Controls on AWS fo...
Mission (Not) Impossible: Applying NIST 800-53 High Impact-Controls on AWS fo...Mission (Not) Impossible: Applying NIST 800-53 High Impact-Controls on AWS fo...
Mission (Not) Impossible: Applying NIST 800-53 High Impact-Controls on AWS fo...
 
Cloud ibrido nella PA
Cloud ibrido nella PACloud ibrido nella PA
Cloud ibrido nella PA
 

Semelhante a How You Can Use AWS Identity Services to Be Successful on Your AWS Cloud Journey

What's New in AWS Security Features
What's New in AWS Security FeaturesWhat's New in AWS Security Features
What's New in AWS Security Features
Amazon Web Services
 
awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...
awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...
awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...
himanipatel524244
 

Semelhante a How You Can Use AWS Identity Services to Be Successful on Your AWS Cloud Journey (20)

SID201 Overview of AWS Identity, Directory, and Access Services
 SID201 Overview of AWS Identity, Directory, and Access Services SID201 Overview of AWS Identity, Directory, and Access Services
SID201 Overview of AWS Identity, Directory, and Access Services
 
Demystifying identity on AWS
Demystifying identity on AWSDemystifying identity on AWS
Demystifying identity on AWS
 
AWS Identity, Directory, and Access Services: An Overview
AWS Identity, Directory, and Access Services: An Overview AWS Identity, Directory, and Access Services: An Overview
AWS Identity, Directory, and Access Services: An Overview
 
Migrating Your AD to the Cloud with AWS Directory Services for Microsoft Acti...
Migrating Your AD to the Cloud with AWS Directory Services for Microsoft Acti...Migrating Your AD to the Cloud with AWS Directory Services for Microsoft Acti...
Migrating Your AD to the Cloud with AWS Directory Services for Microsoft Acti...
 
AWS Identity, Directory, and Access Services: An Overview - SID201 - Chicago ...
AWS Identity, Directory, and Access Services: An Overview - SID201 - Chicago ...AWS Identity, Directory, and Access Services: An Overview - SID201 - Chicago ...
AWS Identity, Directory, and Access Services: An Overview - SID201 - Chicago ...
 
What's New in AWS Security Features
What's New in AWS Security FeaturesWhat's New in AWS Security Features
What's New in AWS Security Features
 
AWSome Day MODULE 4 - Security
AWSome Day MODULE 4 - SecurityAWSome Day MODULE 4 - Security
AWSome Day MODULE 4 - Security
 
AWS Security By Design
AWS Security By DesignAWS Security By Design
AWS Security By Design
 
Introduction to AWS Security
Introduction to AWS SecurityIntroduction to AWS Security
Introduction to AWS Security
 
Best practices for choosing identity solutions for applications + workloads -...
Best practices for choosing identity solutions for applications + workloads -...Best practices for choosing identity solutions for applications + workloads -...
Best practices for choosing identity solutions for applications + workloads -...
 
awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...
awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...
awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...
 
Identity Round Robin Workshop - Serverless Round: Security Week at the SF Loft
Identity Round Robin Workshop - Serverless Round: Security Week at the SF LoftIdentity Round Robin Workshop - Serverless Round: Security Week at the SF Loft
Identity Round Robin Workshop - Serverless Round: Security Week at the SF Loft
 
[REPEAT] Microsoft Active Directory Deep Dive (WIN303-R) - AWS re:Invent 2018
[REPEAT] Microsoft Active Directory Deep Dive (WIN303-R) - AWS re:Invent 2018[REPEAT] Microsoft Active Directory Deep Dive (WIN303-R) - AWS re:Invent 2018
[REPEAT] Microsoft Active Directory Deep Dive (WIN303-R) - AWS re:Invent 2018
 
Introduction to AWS Security
Introduction to AWS SecurityIntroduction to AWS Security
Introduction to AWS Security
 
Introduction to Threat Detection and Remediation on AWS
Introduction to Threat Detection and Remediation on AWSIntroduction to Threat Detection and Remediation on AWS
Introduction to Threat Detection and Remediation on AWS
 
AWSome Day Online 2020_Module 4: Secure your cloud applications
AWSome Day Online 2020_Module 4: Secure your cloud applicationsAWSome Day Online 2020_Module 4: Secure your cloud applications
AWSome Day Online 2020_Module 4: Secure your cloud applications
 
The AWS Shared Responsibility Model in Practice
The AWS Shared Responsibility Model in PracticeThe AWS Shared Responsibility Model in Practice
The AWS Shared Responsibility Model in Practice
 
AWSome Day | Tech Track
AWSome Day | Tech TrackAWSome Day | Tech Track
AWSome Day | Tech Track
 
Jeff Lombardo - Enforcing access control in depth with AWS - v1.2.pdf
Jeff Lombardo - Enforcing access control in depth with AWS - v1.2.pdfJeff Lombardo - Enforcing access control in depth with AWS - v1.2.pdf
Jeff Lombardo - Enforcing access control in depth with AWS - v1.2.pdf
 
The AWS Shared Responsibility Model in Practice
The AWS Shared Responsibility Model in PracticeThe AWS Shared Responsibility Model in Practice
The AWS Shared Responsibility Model in Practice
 

Mais de Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

Mais de Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 
Come costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWSCome costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWS
 
AWS Serverless per startup: come innovare senza preoccuparsi dei server
AWS Serverless per startup: come innovare senza preoccuparsi dei serverAWS Serverless per startup: come innovare senza preoccuparsi dei server
AWS Serverless per startup: come innovare senza preoccuparsi dei server
 
Crea dashboard interattive con Amazon QuickSight
Crea dashboard interattive con Amazon QuickSightCrea dashboard interattive con Amazon QuickSight
Crea dashboard interattive con Amazon QuickSight
 

How You Can Use AWS Identity Services to Be Successful on Your AWS Cloud Journey

  • 1. Pop-up Loft Overview of AWS Identity, Directory, and Access Services Ron Cully Manager, Directory Service Product Management Amazon Web Services
  • 2. Every AWS Cloud journey is unique. Migrating or extending existing infrastructure and applications. Building customer facing cloud-native applications. Going all-in on cloud solutions across the organization. Using the scale of the AWS Cloud to solve new challenges. Requiring unique identity and access management solutions.
  • 3. What to Expect (C) Copyright Jean-Remy Duboc and licensed for reuse under the Creative Commons Attribution-Generic 2.0 License Provide mental model Chart the Cloudscape How to Use IDAS Services
  • 4. Disambiguation Identity and Access Mgmt (the subject) AWS IAM (the service) Authentication, authorization, audit and governance for your cloud workloads Our scope Authenticates and authorizes AWS APIs Includes
  • 5. Identity and Access Management means… Validate identities securely Authentication Manage access using fine-grained policies Authorization Meet compliance requirements Audit/Governance
  • 6. At all levels… Identity and Access Management (the subject) AWS Management Console/APIs AWS Infrastructure AWS Applications Your Applications Developers Admins Security Employees Customers Partners
  • 7. Tenets Mental model for Identity and Access Management services Give you choice Secure, flexible, comprehensive Meet you where you are
  • 8. Benefits of AWS Identity, Directory, and Access Services Superior Security Enable you to build applications and manage access more securely in the AWS Cloud than on premises. Increase Flexibility Offer you options that meet you along your AWS Cloud journey instead of forcing you to adapt to AWS. Comprehensive Breadth of services that help you get started quickly and are feature rich to meet your more advanced needs over time.
  • 10. AWS Identity, Directory, and Access Services AWS Secrets Manager (NEW!) Lifecycle management for application secrets. AWS Identity and Access Management Fine-grained access management for AWS resources. AWS Organizations Policy-based management for multiple AWS accounts. AWS Directory Service Integrates Active Directory in AWS for Windows workloads, AWS resource access, and AWS AWS Single Sign-On Manage single sign-on (SSO) access to multiple AWS accounts and business applications.
  • 11. Broader Security Portfolio AWS Config Rules AWS Lambda Incident response AWS Identity & Access Management (IAM) AWS Organizations AWS Cognito AWS Single Sign-On AWS Directory Service AWS Secrets Manager Identity AWS CloudTrail AWS Config Amazon CloudWatch Amazon GuardDuty VPC Flow Logs Detective control Amazon EC2 Systems Manager AWS Shield AWS Web Application Firewall (WAF) Amazon Inspector Amazon Virtual Private Cloud (VPC) Infrastructure security AWS Key Management Service (KMS) AWS CloudHSM Amazon Macie Certificate Manager Server Side Encryption Data protection
  • 12. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Accounts Account Account Account Account Account Account Account Account Account Account Account AccountAccount Account Account
  • 13. AWS Resources AWS Organizations M Master Account / Administrative root A1 A2 A4 AWS AccountsA3 Organizational Unit (OU)Dev Test Prod Service Control Policies (SCPs)
  • 14. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved SaaS App Account IdP SAML OIDC Federated Users Applications IAM Group IAM Users Security Principals R Root Identity-based Policies EBS EC2 Resource-based Policies S3 SNS ECR KMS SES CognitoOrganizations RDS CloudWatch AD DS AWS IAM Service Control Policies Resulting Permissions Resource-based Policies Identity-based Policies Roles Old School What’s my permission?
  • 15. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved IAM Group IAM Users Federated Users Roles Applications R Root Identity-based Policies AWS IAM How to Use IDAS Services
  • 16. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Roles Identity-based Policies R Root IAM Users IAM Group Federated Users Applications Assign permission to assume roles and apply policies to roles Use root to set up initial admin users only Require strong passwords for users ALWAYS set up multi-factor authentication for Root user and ideally for all other users Don’t embed secrets in code! Use AWS Secrets Manager AWS IAM: Best Practices ************* ************* // Authenticate app User = “App1” Pwd = “App1Pwd” 1X Old School
  • 17. Lifecycle management for secrets such as database credentials and API keys. Rotate Secrets Safely Pay as you goManage access with fine-grained policies Secure and audit secrets centrally AWS Secrets Manager
  • 18. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved User Identity Strategy IdP SAML OIDC Federated Users Have an existing SAML or OIDC infrastructure Don’t need/want Active Directory in the AWS Cloud IAM Group IAM Users Small team, don’t have a directory Have or need Active Directory for users and groups AD Federated Users DS
  • 19. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved AWS Managed AD: User Forest Enable, authenticate, & authorize .NET Applications Server SharePoint Server AD-aware Workloads SQL ServerRemote Desktop Licensing Manager .NET SharePoint SQL Server RD Licensing Enterprise Certificate Authority Certificate Services SaaS Applications Azure AD Amazon WorkSpaces Amazon WorkDocs Amazon WorkMail Amazon QuickSight AWS Management Console Amazon Chime Amazon Connect AWS Apps & Services RDS for SQL Server AWS Managed Microsoft AD SAML authenticate Synchronize users AD FS Server AD FS Azure AD Connect Server Federate ADSync Manage, authenticate, & authorize Domain Join & Manage Amazon EC2 Amazon Windows EC2 instances Amazon Linux EC2 Instances
  • 20. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved AWS Managed AD: User Forest Enable, authenticate, & authorize .NET Applications Server SharePoint Server AD-aware Workloads SQL ServerRemote Desktop Licensing Manager .NET SharePoint SQL Server RD Licensing Enterprise Certificate Authority Certificate Services SaaS Applications Azure AD Amazon WorkSpaces Amazon WorkDocs Amazon WorkMail Amazon QuickSight AWS Management Console Amazon Chime Amazon Connect AWS Apps & Services RDS for SQL Server AWS Managed Microsoft AD Manage, authenticate, & authorize Domain Join & Manage Amazon EC2 Amazon Windows EC2 instances Amazon Linux EC2 Instances On-premises Microsoft Active Directory On-premises user credentials Corporate data center AD FS Server SAML authenticate Synchronize users Azure AD Connect Server VPN Direct Connect or Trust Authenticate
  • 21. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Federation with AD Connector AD Connector SaaS Applications Azure AD Domain Join & Manage On-premises Microsoft Active Directory On-premises user credentials Corporate data centerVPN Direct Connect or AD FS Server SAML authenticate Synchronize users Azure AD Connect Server Authenticate & Proxy LDAP Provision & Authenticate .NET Applications Server SharePoint Server SQL ServerRemote Desktop Licensing Manager Enterprise Certificate Authority AD-aware Workloads .NET SharePoint SQL Server RD Licensing Certificate Services Amazon EC2 Amazon Windows EC2 instances Amazon Linux EC2 Instances Amazon WorkSpaces Amazon WorkDocs Amazon WorkMail Amazon QuickSight AWS Management Console Amazon Chime Amazon Connect AWS Apps & Services RDS for SQL Server
  • 22. AWS Single Sign-On Entitlements AWS SSO Master Account AWS Directory Service Groups Active Directory On-premises Install AWS SSO and map AD groups to defined permissions Grant access to one AWS account, an OU, or the entire Organization Connect AWS Directory Service to on-premises AD AWS Organizations
  • 23. Account SAML or OIDC Federation SaaS Applications Azure AD On-premises Microsoft Active Directory On-premises user credentials Corporate data center AD FS Server SAML authenticate Synchronize users Azure AD Connect Server Account Account AWS IAM End-point for Single Sign-on
  • 25. Pop-up Loft aws.amazon.com/activate Everything and Anything Startups Need to Get Started on AWS