View a markdown version of this page

Security in account access manager - AWS Identity and Access Management

Security in account access manager

This section provides security information specific to account access manager. It complements the information in Security in IAM and AWS STS, which covers security topics applicable to IAM as a whole.

Identity and access management for account access manager

The following sections describe the permissions you need to:

  • Administer account access manager in your organization management account

  • Administer account access manager from a delegated administrator account

Administering account access manager from your organization management account

To administer account access manager settings in the AWS organization management account you need the following permissions:

{ "Version": "2012-10-17", "Statement": [ { "Sid": "AAMCreateApplication", "Effect": "Allow", "Action": "account-access:CreateApplication", "Resource": "*" }, { "Sid": "AAMApplicationAndEntitlementManagement", "Effect": "Allow", "Action": [ "account-access:CreateEntitlement", "account-access:DeleteApplication", "account-access:DeleteEntitlement", "account-access:GetApplication", "account-access:GetEntitlement", "account-access:ListEntitlements", "account-access:ListTagsForResource", "account-access:TagResource", "account-access:UntagResource" ], "Resource": "arn:aws:account-access:*:111122223333:application/*" }, { "Sid": "AAMListApplications", "Effect": "Allow", "Action": "account-access:ListApplications", "Resource": "*" }, { "Sid": "DependentIdentityCenterActions", "Effect": "Allow", "Action": [ "sso:CreateApplication", "sso:DeleteApplication", "sso:DescribeApplication", "sso:DescribeInstance", "sso:DescribeRegion", "sso:ListInstances", "sso:PutApplicationAccessScope", "sso:PutApplicationAssignmentConfiguration", "sso:PutApplicationAuthenticationMethod", "sso:PutApplicationGrant" ], "Resource": "*" }, { "Sid": "DependentIdentityStoreActions", "Effect": "Allow", "Action": [ "identitystore:DescribeGroup", "identitystore:DescribeUser", "identitystore:ListGroupMemberships", "sso-directory:DescribeGroup", "sso-directory:DescribeGroups", "sso-directory:DescribeUser", "sso-directory:DescribeUsers", "sso-directory:ListGroupsForUser", "sso-directory:ListMembersInGroup", "sso-directory:SearchGroups", "sso-directory:SearchUsers" ], "Resource": "*" }, { "Sid": "DependentOrganizationsActions", "Effect": "Allow", "Action": [ "organizations:DescribeAccount", "organizations:DescribeOrganization", "organizations:ListAccounts", "organizations:ListAccountsForParent", "organizations:ListAWSServiceAccessForOrganization", "organizations:ListDelegatedAdministrators", "organizations:ListOrganizationalUnitsForParent", "organizations:ListRoots" ], "Resource": "*" }, { "Sid": "DependentKMSActions", "Effect": "Allow", "Action": "kms:Decrypt", "Resource": "*" }, { "Sid": "CreateServiceLinkedRole", "Effect": "Allow", "Action": "iam:CreateServiceLinkedRole", "Resource": "arn:aws:iam::111122223333:role/aws-service-role/account-access.amazonaws.com/AWSServiceRoleForAccountAccessManager", "Condition": { "StringEquals": { "iam:AWSServiceName": "account-access.amazonaws.com" } } } ] }

Optional: To constrain account-access:CreateApplication by tag, replace the AAMCreateApplication statement with:

{ "Sid": "AAMCreateApplicationConstrainedByTag", "Effect": "Allow", "Action": "account-access:CreateApplication", "Resource": "*", "Condition": { "StringEquals": { "aws:RequestTag/Environment": "Production" }, "ForAllValues:StringEquals": { "aws:TagKeys": [ "Environment" ] } } }

Optional: To manage and register delegated administrators for account access manager, add:

{ "Sid": "ManageDelegatedAdministrator", "Effect": "Allow", "Action": [ "organizations:DeregisterDelegatedAdministrator", "organizations:RegisterDelegatedAdministrator" ], "Resource": "*", "Condition": { "StringEquals": { "organizations:ServicePrincipal": "account-access.amazonaws.com" } } }

To assign IAM roles to your workforce users and groups from the AWS organization management account without administering account access manager settings you need the following permissions:

{ "Version": "2012-10-17", "Statement": [ { "Sid": "AAMManageEntitlementsOnly", "Effect": "Allow", "Action": [ "account-access:CreateEntitlement", "account-access:DeleteEntitlement", "account-access:GetApplication", "account-access:GetEntitlement", "account-access:ListEntitlements" ], "Resource": "arn:aws:account-access:*:111122223333:application/*" }, { "Sid": "AAMListApplications", "Effect": "Allow", "Action": "account-access:ListApplications", "Resource": "*" }, { "Sid": "DependentIdentityCenterActions", "Effect": "Allow", "Action": "sso:ListInstances", "Resource": "*" }, { "Sid": "DependentIdentityStoreActions", "Effect": "Allow", "Action": [ "identitystore:DescribeGroup", "identitystore:DescribeUser", "identitystore:ListGroupMemberships", "sso-directory:DescribeGroup", "sso-directory:DescribeGroups", "sso-directory:DescribeUser", "sso-directory:DescribeUsers", "sso-directory:ListGroupsForUser", "sso-directory:ListMembersInGroup", "sso-directory:SearchGroups", "sso-directory:SearchUsers" ], "Resource": "*" }, { "Sid": "DependentOrganizationsActions", "Effect": "Allow", "Action": [ "organizations:DescribeAccount", "organizations:DescribeOrganization", "organizations:ListAccounts", "organizations:ListAccountsForParent", "organizations:ListAWSServiceAccessForOrganization", "organizations:ListDelegatedAdministrators", "organizations:ListOrganizationalUnitsForParent", "organizations:ListRoots" ], "Resource": "*" } ] }

Administering account access manager in a delegated administration account

To administer account access manager settings from a delegated administration account you need the following permissions:

{ "Version": "2012-10-17", "Statement": [ { "Sid": "AAMDelegatedAdminManagement", "Effect": "Allow", "Action": [ "account-access:CreateEntitlement", "account-access:DeleteEntitlement", "account-access:GetApplication", "account-access:GetEntitlement", "account-access:ListEntitlements", "account-access:ListTagsForResource", "account-access:TagResource", "account-access:UntagResource" ], "Resource": "arn:aws:account-access:*:111122223333:application/*" }, { "Sid": "AAMListApplications", "Effect": "Allow", "Action": "account-access:ListApplications", "Resource": "*" }, { "Sid": "DependentIdentityCenterActions", "Effect": "Allow", "Action": [ "sso:DescribeApplication", "sso:DescribeInstance", "sso:DescribeRegion", "sso:ListInstances" ], "Resource": "*" }, { "Sid": "DependentIdentityStoreActions", "Effect": "Allow", "Action": [ "identitystore:DescribeGroup", "identitystore:DescribeUser", "identitystore:ListGroupMemberships", "sso-directory:DescribeGroup", "sso-directory:DescribeGroups", "sso-directory:DescribeUser", "sso-directory:DescribeUsers", "sso-directory:ListGroupsForUser", "sso-directory:ListMembersInGroup", "sso-directory:SearchGroups", "sso-directory:SearchUsers" ], "Resource": "*" }, { "Sid": "DependentOrganizationsActions", "Effect": "Allow", "Action": [ "organizations:DescribeAccount", "organizations:DescribeOrganization", "organizations:ListAccounts", "organizations:ListAccountsForParent", "organizations:ListAWSServiceAccessForOrganization", "organizations:ListDelegatedAdministrators", "organizations:ListOrganizationalUnitsForParent", "organizations:ListRoots" ], "Resource": "*" } ] }

To assign IAM roles to workforce users and groups from a delegated administration account without administering account access manager settings you need the following permissions:

{ "Version": "2012-10-17", "Statement": [ { "Sid": "AAMManageEntitlementsOnly", "Effect": "Allow", "Action": [ "account-access:CreateEntitlement", "account-access:DeleteEntitlement", "account-access:GetApplication", "account-access:GetEntitlement", "account-access:ListEntitlements" ], "Resource": "arn:aws:account-access:*:111122223333:application/*" }, { "Sid": "AAMListApplications", "Effect": "Allow", "Action": "account-access:ListApplications", "Resource": "*" }, { "Sid": "DependentIdentityCenterActions", "Effect": "Allow", "Action": "sso:ListInstances", "Resource": "*" }, { "Sid": "DependentIdentityStoreActions", "Effect": "Allow", "Action": [ "identitystore:DescribeGroup", "identitystore:DescribeUser", "identitystore:ListGroupMemberships", "sso-directory:DescribeGroup", "sso-directory:DescribeGroups", "sso-directory:DescribeUser", "sso-directory:DescribeUsers", "sso-directory:ListGroupsForUser", "sso-directory:ListMembersInGroup", "sso-directory:SearchGroups", "sso-directory:SearchUsers" ], "Resource": "*" }, { "Sid": "DependentOrganizationsActions", "Effect": "Allow", "Action": [ "organizations:DescribeAccount", "organizations:DescribeOrganization", "organizations:ListAccounts", "organizations:ListAccountsForParent", "organizations:ListAWSServiceAccessForOrganization", "organizations:ListDelegatedAdministrators", "organizations:ListOrganizationalUnitsForParent", "organizations:ListRoots" ], "Resource": "*" } ] }

Data protection in account access manager

This section complements the information provided in Data protection in AWS Identity and Access Management with additional details specific to account access manager.

Use of IAM Identity Center user and group data

Account access manager uses user and group data from IAM Identity Center to manage account assignments. However, account access manager stores and logs only AWS-generated identifiers (user ID and group ID) — it does not store or log user names, email addresses, or other personal attributes.

Logging and monitoring in account access manager

Account access manager uses its own API namespace (account-access) and logs API calls through CloudTrail.

For more information about CloudTrail, see the AWS CloudTrail User Guide.