All technological notes.
IAM Identity CenterIAM Identity Center
AWS Single Sign-On)SAML2.0-enabled applicationsIdentity providers
IAM Identity CenterActive Directory (AD), OneLogin, Okta…


不同方法应对不同场景来实现权限的精确控制.
Permission Sets(Organ)
IAM Policies assigned to users and groups to define AWS accessAWS Organization
Application Assignments(SAML application)
SAML 2.0 business applications (Salesforce, Box, Microsoft 365, …)Attribute-Based Access Control (ABAC)(built-in)
IAM Identity Center Identity Store