4 ms·
This is a lot harder to do if you have lots of AWS accounts and create new ones over time on-demand (e.g. AWS account per team).
by dmlittle 6y ago
This is a lot harder to do if you have lots of AWS accounts and create new ones over time on-demand (e.g. AWS account per team).
- NovemberWhiskey 6y agoUse Organizations. If you’re creating new standalone independent accounts for teams you’re just seeking yourself up for some kind of billing/security/governance catastrophe down the road.
- dmlittle 6y agoI was referring to the root accounts in your organization. The blast radius is more limited, but still a root account that has access to everything within that AWS account.
- time0ut 6y agoYou can restrict what the root account can do in a member account using SCPs as an additional safeguard as well.