Auth Account role configuration

Now we're going to create two roles. These roles will correspond to the groups we defined in Active Directory:

  • AWSPowerUser: CanAssumePowerUser
  • AWSReadOnly: CanAssumeReadOnly
  1. Start by creating the CanAssumePowerUser role first:
  1. We want this role to be an AWS Directory Service role, so be sure to select it before proceeding:
  1. Attach the AllowAssumeRole policy we have already created to this role:
Hint: You can filter the roles using the search box to make finding them easier.
  1. Click Create Role to confirm: ...

Get AWS Administration Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.