AWS Identity and Access Management (IAM) | Billing Flashcards
How does identity federation using AWS Directory Service differ from using a third-party identity management solution?
Billing
AWS Identity and Access Management (IAM) | Security, Identity & Compliance
If you want your federated users to be able to access only the AWS Management Console, using AWS Directory Service provides similar capabilities compared to using a third-party identity management solution. End users are able to sign in using their existing corporate credentials and access the AWS Management Console. Because AWS Directory Service is a managed service, customers do not need to set up or manage federation infrastructure, but rather need to create an AD Connector directory to integrate with their on-premises directory. If you are interested in providing your federated users access to AWS APIs, use a third-party offering, or deploy your own proxy server.
Does AWS Billing provide aggregated usage and cost breakdowns by user?
Billing
AWS Identity and Access Management (IAM) | Security, Identity & Compliance
No, this is not currently supported.
Does the IAM service cost anything?
Billing
AWS Identity and Access Management (IAM) | Security, Identity & Compliance
No, this is a feature of your AWS account provided at no additional charge.
Who pays for usage incurred by users under an AWS Account?
Billing
AWS Identity and Access Management (IAM) | Security, Identity & Compliance
The AWS account owner controls and is responsible for all usage, data, and resources under the account.
Is billable user activity logged in AWS usage data?
Billing
AWS Identity and Access Management (IAM) | Security, Identity & Compliance
Not currently. This is planned for a future release.
How does IAM compare with Consolidated Billing?
Billing
AWS Identity and Access Management (IAM) | Security, Identity & Compliance
IAM and Consolidated Billing are complementary features. Consolidated Billing enables you to consolidate payment for multiple AWS accounts within your company by designating a single paying account. The scope of IAM is not related to Consolidated Billing. A user exists within the confines of an AWS account and does not have permissions across linked accounts. For more details, see Paying Bills for Multiple Accounts Using Consolidated Billing.