Amazon Web Service - Replace IAM Users with AWS SSO

แชร์
ฝัง
  • เผยแพร่เมื่อ 6 ก.ย. 2024

ความคิดเห็น • 62

  • @samb2543
    @samb2543 3 ปีที่แล้ว +4

    This is the best explanation I've seen of SSO

  • @Unerty
    @Unerty 2 ปีที่แล้ว +3

    This gives me "My name is Giovanni Giorgio, but everybody calls me Giorgio" vibes. By the way, thanks for the great video!

    • @robertabanks
      @robertabanks 7 หลายเดือนก่อน

      so we put a click on the 24-track

  • @sreaswar
    @sreaswar 2 ปีที่แล้ว +3

    That was so clear and well explained. Thanks for sharing

    • @cloudonaut
      @cloudonaut  2 ปีที่แล้ว +1

      Thanks a lot for your motivating feedback!

  • @thestart709
    @thestart709 4 หลายเดือนก่อน

    The Organisation is created from the AWS root account so I guess the SSO should be activated from the AWS root account where the Organisation exists?

    • @cloudonaut
      @cloudonaut  4 หลายเดือนก่อน

      Yes, root account or a delegated admin account, see docs.aws.amazon.com/singlesignon/latest/userguide/delegated-admin.html

  • @ravitejateja2071
    @ravitejateja2071 3 หลายเดือนก่อน

    Thank you for the great video. Any idea if it is possible to automate the process to auto refresh the temporary credentials? If we want to try out SSM with SSO, if we do aws configure sso and set up profile, every time it asks for approval from browser. Any way we can automate this to avoid browser approvals?

    • @cloudonaut
      @cloudonaut  3 หลายเดือนก่อน

      Thanks for the feedback. I'm not aware of a way to automate refreshing the credentials.

  • @mohammadjavadraadi2825
    @mohammadjavadraadi2825 2 ปีที่แล้ว +1

    Thank you for sharing. Really appreciate it.

    • @cloudonaut
      @cloudonaut  2 ปีที่แล้ว

      Glad you enjoyed it!

  • @taraskostyuk7076
    @taraskostyuk7076 3 ปีที่แล้ว +2

    SSO is supported not in all AWS regions. So SSO can not be used if using the unsupported region is required?

    • @cloudonaut
      @cloudonaut  3 ปีที่แล้ว +2

      You can still use all AWS regions. But SSO can only be deployed into some of them. See docs.aws.amazon.com/singlesignon/latest/userguide/regions.html

    • @MACODJ
      @MACODJ 2 ปีที่แล้ว

      @@cloudonaut and italy??

  • @thestart709
    @thestart709 4 หลายเดือนก่อน

    what about if we want to terraform apply(CI) on specific AWS account? would you create an SSO user like e.x. deployer from which you would run aws sso get-role-credentials to get temporary credentials and apply terraform?

    • @cloudonaut
      @cloudonaut  4 หลายเดือนก่อน

      Depend on your CI solution. If you use GitHub, you can use docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-amazon-web-services

  • @SethArt
    @SethArt 3 ปีที่แล้ว +1

    Thanks for sharing! Really helpful.

  • @pippopeppe83
    @pippopeppe83 2 ปีที่แล้ว +1

    Great explanetion

    • @cloudonaut
      @cloudonaut  2 ปีที่แล้ว

      Glad you liked it

  • @sudsrmsee
    @sudsrmsee ปีที่แล้ว

    Thanks for clarity,,,still, I have one doubt,,, if OU already has SCP then is it possible to integrate sso with OU with new permission sets ?

    • @cloudonaut
      @cloudonaut  ปีที่แล้ว +1

      You are mixing two distinct topics: SSO permission polices are used to generate IAM roles/policies an SCP are in effect above that.

  • @johanneskoller7089
    @johanneskoller7089 ปีที่แล้ว

    Very great and usefull video

  • @jumaal-maskari6010
    @jumaal-maskari6010 ปีที่แล้ว

    Great work, thanks

  • @Anshie007
    @Anshie007 ปีที่แล้ว

    Absolutely great video !
    One question if we don't have AWS organizations setup, we can still work with this setup for the same account right ?
    Also as recommendation, would have been cherry on top if you could add On prem AD as identity provider as that's the most common use case.
    Thanks again !

    • @cloudonaut
      @cloudonaut  ปีที่แล้ว

      Your AWS account must be managed by AWS Organizations. If you haven't set up an organization, you don't have to. When you enable IAM Identity Center, you will choose whether to have AWS create an organization for you.

  • @loumarich3562
    @loumarich3562 2 ปีที่แล้ว

    What if your not getting connected to the AWS console after you select your accou to login? What to troubleshoot?

    • @cloudonaut
      @cloudonaut  2 ปีที่แล้ว +1

      I recommend to open your browser's developer tools and check the error codes and messages of the outgoing HTTPS requests.

  • @TechLeadEngineer
    @TechLeadEngineer ปีที่แล้ว

    Great video tutorial, thank you. Quick question, how do I use an SSO user to login with long-term credential? I have an API that needs to login to AWS to view data of a KDS. This is an automated process and so I need to use a proxy account coming from identity source (Azure AD in our case), however all the AWS docs I found only use IAM with short-term credential. Any idea? Thanks in advance.

  • @RowanSheridan
    @RowanSheridan 2 ปีที่แล้ว

    How do you guys not have more subscribers!?

    • @cloudonaut
      @cloudonaut  2 ปีที่แล้ว

      We are working on it :)

  • @suhasvengilat1026
    @suhasvengilat1026 3 ปีที่แล้ว

    Really superb - Thank you

  • @MACODJ
    @MACODJ 2 ปีที่แล้ว

    I cant register a new account to access at the aws service! Where is the bug? Please help, i cant use aws amazon

    • @cloudonaut
      @cloudonaut  2 ปีที่แล้ว

      Sorry, we cannot help with that. Please contact AWS support.

  • @iaroslavdavydiak6439
    @iaroslavdavydiak6439 2 ปีที่แล้ว +1

    Awesome explanation. Thanks!

    • @cloudonaut
      @cloudonaut  2 ปีที่แล้ว

      Great! Are you using AWS SSO already?

  • @edipocdf
    @edipocdf 2 ปีที่แล้ว

    tks a lot, very god video

  • @akimyucel3900
    @akimyucel3900 2 ปีที่แล้ว

    Good content, thank you

  • @thyponzoni
    @thyponzoni 3 ปีที่แล้ว +1

    So, is AWS SSO not advised for larger businesses? We use IAM with an identity account with users and groups and need to assume roles in other accounts. The process isn't very smooth IMO. We have over 400 engineers. Thanks for the great content!

    • @cloudonaut
      @cloudonaut  3 ปีที่แล้ว +2

      You can use SSO in larger orgs as well these days. Likely in combination with (Azure) AD.

    • @modesoliman
      @modesoliman 2 ปีที่แล้ว

      @@cloudonaut should we create the IAM roles for all engineers again manually? or there is a way i can migrate current roles from iam users and groups roles to SSO ?

    • @cloudonaut
      @cloudonaut  2 ปีที่แล้ว +1

      @@modesoliman Not sure what you mean be creating roles manually. The roles are fully managed via SSO (see permission sets docs.aws.amazon.com/singlesignon/latest/userguide/howtocreatepermissionset.html).

    • @modesoliman
      @modesoliman 2 ปีที่แล้ว

      @@cloudonaut i mean if users have custom roles not the predefined , should i recreate them manually or there is a way so i can migrate them from iam to sso console?

    • @cloudonaut
      @cloudonaut  2 ปีที่แล้ว

      @@modesoliman It is possible to copy the IAM policies from your IAM roles to AWS SSO.

  • @rajeshom5129
    @rajeshom5129 2 ปีที่แล้ว

    I want to use those access key and secret key in python script to connect with Boto3 ,can you please help how can i write such a python code to work with AWS services with SSO

    • @cloudonaut
      @cloudonaut  2 ปีที่แล้ว

      Copy&Paste the environment variables from AWS SSO or check out stackoverflow.com/questions/62311866/how-to-use-the-aws-python-sdk-while-connecting-via-sso-credentials.

  • @wisunhi77
    @wisunhi77 2 ปีที่แล้ว

    can you migrate the current IAM users to AWS SSO?

    • @cloudonaut
      @cloudonaut  2 ปีที่แล้ว +1

      We are not aware of a way to migrate IAM users to SSO, unfortunately.

    • @wisunhi77
      @wisunhi77 2 ปีที่แล้ว

      @@cloudonaut Got it thanks!

  • @supersoniq4102
    @supersoniq4102 ปีที่แล้ว

    Rename this video to "SSO MasterClass"

    • @cloudonaut
      @cloudonaut  ปีที่แล้ว

      Thanks a lot for your feedback! :D

  • @pabloin
    @pabloin 3 ปีที่แล้ว +1

    great explanation! Thanks!

  • @sellerym
    @sellerym 2 ปีที่แล้ว

    Excellent video, thank you!

    • @cloudonaut
      @cloudonaut  2 ปีที่แล้ว

      Thanks a lot for your feedback!