Identity Federation lets users from outside AWS (corporate Active Directory, Google, Okta, GitHub) access AWS resources without creating individual IAM users. Instead, external identities are mapped to IAM roles via federation protocols.
An AWS identity with temporary credentials that can be assumed by users, services, or applications to perform actions without long-term access keys.
The process of obtaining temporary security credentials by calling AWS STS to take on the permissions of an IAM role.
A centralized authentication mechanism that allows users to log in once and access multiple AWS accounts and applications without re-entering credentials.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.