Identity Center 2 Flashcards

1
Q

Provisioning

What is “Provisioning”?

A

Making users and groups available in Identity Center (creating by hand, connecting to an IdP) and syncing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Provisioning

So why not just use Federation instead?

A

Would set it up per-application. This works across apps and across AWS accounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Provisioning

Two types of Provisioning with external IdP?

A

Automatic and Manual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Provisioning

Why not have Identity Center just search an IdP like with AD?

A

SAML doesn’t support search feature. No auto-discovery.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Provisioning

How does manual provisioning work with an external IdP?

A

Manually create usernames in Identity Center matching the external IdP.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Provisioning

how does automatic provisioning work with an external IdP?

A

Has to support SCIM (cross-domain sync protocol). Syncs things automatically.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Access and Security

What user attributes are generally kept in Identity Center?

A

Common ones, but never credentials: name, phone, email, …

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Access and Security

How does app access security work with Organizations?

A

Set perms using SCPs in Org to control which attributes which apps have access to.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Access and Security

How do you control which apps are available in which AWS accounts?

A

Organizations: enable in management account for access by all member accounts, or in individual member accounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Access and Security

What creds does Identity Center keep/maintain?

A

One for Identity Center, another for the individual apps to exchange with them for SSO.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Access and Security

How long do the stored creds in Identity Center last?

A

I.C. creds are up to 7 days, app creds refresh hourly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Access and Security

How do the two creds work?

A

I.C. creds used to acquire app creds and refresh them on-going.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Access and Security

What is a Permission Set?

A

Template that defines IAM Policies. Assign PS to users/groups. That user gets all the policies thru SSO.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Access and Security

Two types of Permission Sets?

A

Predefined (by AWS, like Admin or Readonly) and Custom (you build from scratch)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Access and Security

Concrete example of a Permission Set?

A

“DBOps” has Dynamo, RDS, and Redshift managed R/W Policies, use the P.S. across AWS accounts in the console.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Access and Security

What do you attach to a Permission Set so it restricts what users can do?

A

AWS managed Policies, custom Policies, and Permissions Boundaries

17
Q

Access and Security

What does “Provisioned” mean for a Permission Set?

A

It’s associated with a user or group

18
Q

Identity Center and Active Directory

What if you have multiple Active Directories to coordinate?

A

Use AWS Directory Service (which is AD). Set up connector to other AD Domains using AD Trust.

19
Q

Identity Center and Active Directory

What if you don’t want to use AWS Directory Service? That’s just another AD to maintain…

A

AWS AD Connector: an AD proxy that forwards requests to your on-prem AD (for example).

20
Q

Identity Center and Active Directory

How does sync work with AD?

A

Two ways, you pick one: AD Sync, or AD Configurable Sync. Both keep data up to date by actively syncing between Identity Center and AD.

21
Q

Identity Center and Active Directory

How does AD Sync work?

A

When assigning users or groups to an app, AD Sync searches AD directly, then keeps those users/groups in Identity Center.

22
Q

Identity Center and Active Directory

How does AD Configurable Sync work?

A

First pick users/groups to keep in sync in Identity Center. When assigning u/g to an app, only uses u/g synced to Identity Center (doesn’t search AD).