Auth Account role configuration

Now we're going to create two roles. These roles will correspond to the groups we defined in Active Directory:

  • AWSPowerUser: CanAssumePowerUser
  • AWSReadOnly: CanAssumeReadOnly
  1. Start by creating the CanAssumePowerUser role first:
  1. We want this role to be an AWS Directory Service role, so be sure to select it before proceeding:
  1. Attach the AllowAssumeRole policy we have already created to this role:
Hint: You can filter the roles using the search box to make finding them easier.
  1. Click Create Role to confirm:
  1. Now go ahead and do exactly the same for the CanAssumeReadOnly role. Again, attach the AllowAssumeRole policy we created earlier:
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset