Glossary

    Cross-Account Access

    Identity & Access

    Cross-Account Access allows users, roles, or services in one AWS account to access resources in another account. The recommended approach is creating an IAM role in the target account with a trust policy that allows the source account to assume it.

    Methods

    • IAM Roles: the recommended approach; temporary credentials, auditable via CloudTrail
    • Resource-based policies: S3 bucket policies, SQS queue policies, KMS key policies can grant cross-account access directly
    • AWS RAM: share resources (subnets, Transit Gateways, License Manager configs) across accounts
    • AWS Organizations: trusted access for services like CloudTrail, Config, GuardDuty across the org

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.