Auth Account policy configuration

We now we need to create a policy in our Auth Account. Remember that this is the account that the users Lucille and Buster will initially log in to when visiting the AWS console. We actually want to give them extremely limited access to this account. In fact, the only thing we're going to let them do is attempt to switch to a role in the application account.

  1. Visit the IAM console in the Auth Account and create a new policy:
AWS refers to this type of policy as a Customer Managed Policy.
  1. Call this policy AllowAssumeRole. Give it a description to help you remember what it's for. Then apply the following policy ...

Get AWS Administration Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.