Assign permissions

Assign Access Rights to Users and Groups

To configure access rights for AWS accounts within SSO groups based on specific job functionalities, follow the steps below:

Account and Group Configuration

Accounts Groups Job Function Policy
Management Account, shared-services, logging,security AWS-Shared-Services-Admin; AWS-Security-Admin; AWS-Logging-Admin AdministratorAccess
Management Account, shared-services, logging, security AWS-Shared-Services-Read-Only; AWS-Security-Read-Only; AWS-Logging-Read-Only SecurityAudit

Instructions

  1. Open the AWS SSO Console and navigate to the AWS accounts section in the left sidebar.

  2. In the AWS organization tab, locate the list of AWS accounts. Choose one or more accounts to which you want to assign access (e.g., Management Account, shared-services, logging, and security). Then click on Assign users or groups.

    AWS Account

  3. Select the relevant groups and click Next.

    AWS Account

  4. Choose the desired Permission set.

    AWS Account

  5. Click Submit.

    AWS Account

  6. Repeat the same process for the Security Account.

    AWS Account

  7. Select the groups and click Next.

    AWS Account

  8. Choose the Permission set and click Next.

    AWS Account

  9. Click Submit.

    AWS Account

  10. Congratulations! You have successfully configured AWS SSO access.

    AWS Account