Step 3: Create an administrative permission set - AWS Setup

Step 3: Create an administrative permission set

Permission sets are stored in IAM Identity Center and define the level of access that users and groups have to an AWS account. Perform the following steps to create a permission set that grants administrative permissions.

  1. Sign in to the AWS Management Console as the account owner by choosing Root user and entering your AWS account email address. On the next page, enter your password.

  2. Open the IAM Identity Center console.

  3. In the IAM Identity Center navigation pane, under Multi-account permissions, choose Permission sets.

  4. Choose Create permission set.

  5. For Step 1: Select permission set type, on the Select permission set type page, keep the default settings and choose Next. The default settings grant full access to AWS services and resources using the AdministratorAccess predefined permission set.

    Note

    The predefined AdministratorAccess permission set uses the AdministratorAccess AWS managed policy.

  6. For Step 2: Specify permission set details, on the Specify permission set details page, keep the default settings and choose Next. The default setting limits your session to one hour.

  7. For Step 3: Review and create, on the Review and create page, do the following:

    1. Review the permission set type and confirm that it is AdministratorAccess.

    2. Review the AWS managed policy and confirm that it is AdministratorAccess.

    3. Choose Create.