4 ms·
I have seen numerous companies get burned because they were sharing a single login on AWS. This is a welcome improvement toward practically managing such an imp
by pselbert 10y ago
I have seen numerous companies get burned because they were sharing a single login on AWS. This is a welcome improvement toward practically managing such an important resource for many teams.
- partiallypro 10y agoIAM was already built into AWS, so that's sort of their own fault for not utilizing that feature. Unless you mean this in a different way, but using a single login was not needed in the past. This is a little different. Sorry, but it's true.
- ajhayes 10y agoI wholeheartedly agree. IAM has been readily available to provision individual users on the AWS accounts for quite some time now. Sharing access to the root account is a bad practice. Ideally, the root account should have MFA enabled, all root access keys should be deleted, and individual users should have their own usernames provisioned via IAM with the principle of least privilege applied.
- rbirkby 10y agoExcept if you need to use AWS services such as AWIS which requires root account access keys...