Hi, I'm Ask INFA!
What would you like to know?
ASK INFAPreview
Please to access Ask INFA.

How to configure assume roles for Amazon resources

How to configure assume roles for Amazon resources

Configure assume role on the AWS console

Configure assume role on the AWS console

You can configure an user in an account to assume a role in another account and access specific resources that belong to the account.
A user in account
3755-6920-9379
(account A) can assume a role in account
0061-0221-4893
(account B) to access specific resources of account B.
Perform the following steps on the AWS console to configure an assume role when the IAM user and the IAM role are in different accounts:
  1. Log in to the
    AWS Console
    .
  2. Click
    Dashboard
    from the left panel. The
    AWS Service
    dashboard page appears.
  3. Click
    IAM
    . The
    Welcome to Identity and Access Management
    page appears.
  4. Click
    Users
    from the left panel.
    Create an IAM user and attach a policy to the IAM user.
    The following image shows the sample of configuring an assume role on the AWS console:
    Create an IAM user and attach a policy.
  5. Click
    Policies
    from the left panel.
    The
    Policies
    page appears.
    The following image shows a sample policy attached to the IAM user in account A:
    The image shows a sample poilcy attached to IAM user.
  6. Define an IAM role in account B. Click
    Roles
    from the left panel. Configure the policies for the IAM role that you configured when the IAM user and the IAM role were in the same account.
  7. Click
    Trust relationships
    tab to define the trust relationship within the AWS account.
    The following image shows that a user from account A is trusted to assume the role that you defined in account B:
    The image shows the user in account A trusted to assume the role defined in account B.

0 COMMENTS

We’d like to hear from you!