Glossary

    Confused Deputy Problem

    Identity & Access

    The Confused Deputy Problem occurs when a trusted entity (the "deputy") is manipulated into performing actions on behalf of an unauthorized party. In AWS, this typically happens with cross-account roles: a third-party service that assumes a role in your account could be tricked by another customer into using your role instead of theirs.

    Prevention: External ID

    AWS recommends using the sts:ExternalId condition in your role's trust policy. The external ID is a shared secret between you and the third party - the deputy must present it when assuming the role, preventing unauthorized parties from using the same role.

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.