Michael Chan Profile picture
Dec 4, 2019 22 tweets 15 min read
⏱️Starting now! ⏱️ @AWSIdentity – presenting our session SEC316 with Brigid @bjohnso5y on Access Control Confidence. 💪⚡ I will be live tweeting the highlights!
@AWSIdentity @bjohnso5y Access control is a journey towards least privilege. Brigid is going to share with us how to make it a confident one.
@AWSIdentity @bjohnso5y Access control confidence. Brigid breaks it down into three parts – permission guardrails, attribute-based access control, and reining in permissions using analytics.
@AWSIdentity @bjohnso5y Brigid said we are going to get nerdy with some JSON policies in the next hour! Can’t wait! 😂
@AWSIdentity @bjohnso5y Quick review of #AWSIAM permissions – two parts: Your job is specification. AWS’s job is enforcement.
@AWSIdentity @bjohnso5y Now we are snapping for the least privilege poem. I feel inspired!
@AWSIdentity @bjohnso5y Moving on to permission guardrails. Pro-tip: use service control policies for common restrictions across your organization. Including restricting regions and powerful actions.
@AWSIdentity @bjohnso5y 📹 Live Demo! 📹 Brigid demonstrates how someone with full access cannot 🛑 create a resource in an unapproved region. Why? Because the SCP she enabled. Pro-tip use the RequestRegion condition key.
@AWSIdentity @bjohnso5y Live Demo! Brigid demonstrates how someone with full access cannot create a resource in an unapproved region. Why? Because the SCP she enabled. Pro-tip use the RequestRegion condition key!
@AWSIdentity @bjohnso5y Moving to Brigid’s favorite topic: fine-grained permissions at scale with attribute-based access control, aka ABAC!
@AWSIdentity @bjohnso5y Brigid breaks down ABAC. Attributes on users, attributes on resources, and a policy to match say “allow access if they match.” Permissions automatically apply, no policy updates required!
@AWSIdentity @bjohnso5y Lots of tools in your ABAC toolbox including principal tags, session tags, resource tags, tag policies, and IAM policies. Pro-tip is to use ${PrincipalTag/tag-key} as variable in your policies.
@AWSIdentity @bjohnso5y She’s diving into session tags, a new IAM feature. “With session tags your identity no longer goes poof 💨 when you federate into AWS. Your IdP becomes the source of truth for access control in AWS.”
@AWSIdentity @bjohnso5y 📹 Live Demo! 📹 Brigid shows how a user from @pingidentity federates in to AWS with attributes and creates and manages workloads with their project tag.
@AWSIdentity @bjohnso5y @pingidentity We are seeing project #pickles 🐴 in action! Who knew horses and access control could go so well together.
@AWSIdentity @bjohnso5y @pingidentity 🚶‍♀️Moving on to reining in permissions using analytics. Our tools 🛠️ include role and access key last used, service last used, and the new access analyzer!
@AWSIdentity @bjohnso5y @pingidentity Brigid says to channel your inner Marie Kondo. Find roles and permissions that don’t bring you joy, say thank you 🙏, and then let them go.
@AWSIdentity @bjohnso5y @pingidentity 📹 Live Demo! 📹 Brigid is finding a lot of roles and permissions in her account that don’t bring her joy.
@AWSIdentity @bjohnso5y @pingidentity Here we go with IAM Access Analyzer! Certainty, comprehensive, and continuously monitors for cross account access.
@AWSIdentity @bjohnso5y @pingidentity 📹 Live Demo again! 📹 Using access analyzer to find permissions with broad access and then scope them down. Pro-tip use the principalOUPath condition key.
@AWSIdentity @bjohnso5y @pingidentity That’s a wrap 🎁! Check out all the new access control functionality recently launched and tune into YouTube for the whole talk. Thanks for listening, for your time, and have a great #reinvent! @bjohnso5y
@AWSIdentity @bjohnso5y @pingidentity And That’s a wrap 🎁! Check out all the new access control functionality recently launched and tune into YouTube for the whole talk. Thank you for listening, for your time, and have a great #reinvent!

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Michael Chan

Michael Chan Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @mchancloud

Aug 24, 2021
🏇 Starting in a few minutes: "Building for the future with @AWSIdentity Services" with Karen Haberkorn, Director of Product Management for AWS Identity 💫 I'll be tweeting the highlights. @AWSIdentity @AWSSecurityInfo #reInforce Image
1/ Building for the future with @AWSIdentity Services: Karen notes our exceptional year - not just for humans, but also for companies, who have shifted to accommodate remote work; a shift to remote identities and their access controls. @AWSIdentity @AWSSecurityInfo #reInforce
3/ "ZT is a conceptual model and an associated set of mechanisms that focus on providing security controls around digital assets that do not solely or fundamentally depend on traditional network controls or network perimeters." @AWSIdentity @AWSSecurityInfo #reInforce
Read 29 tweets
Jun 21, 2021
1/ 📣🎉 @Identiverse, the premier conference for identity professionals, begins today! AWS is a sponsor and will be presenting in-person and live sessions the next few weeks. For those who are attending, here's a thread of the sessions not to miss. @AWSIdentity
2/ And if you're not attending, be sure to check this page in the following weeks for the recorded sessions: identiverse.gallery.video
3/ Here's the sessions! All times are MDT:

Fostering Identity Excellence (Keynote): Tue 6/22, 10am - @Sarah_Cecc
identiverse.com/idv2021/sessio…
Read 9 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(