AWS singlesignon: Added guidance for using account access manager with IAM
Summary
Documentation added for using account access manager when permission sets lack features like custom trust policies or role tags.
Security assessment
Adds documentation for security-related IAM features (trust policies, role tags) but doesn't address a specific vulnerability.
Evidence
+If your access management requires capabilities beyond what permission sets offer — such as custom trust policies, role tags, or configurable role paths — you can use [account access manager](https://docs.aws.amazon.com/IAM/latest/UserGuide/account-access-manager.html) in IAM.
Diff
diff --git a/singlesignon/latest/userguide/permissionsetsconcept.md b/singlesignon/latest/userguide/permissionsetsconcept.md index e6d7bbb59..84ac901c5 100644 --- a//singlesignon/latest/userguide/permissionsetsconcept.md +++ b//singlesignon/latest/userguide/permissionsetsconcept.md @@ -22,0 +23,2 @@ To create a permission set, see [Create, manage, and delete permission sets](./p +If your access management requires capabilities beyond what permission sets offer — such as custom trust policies, role tags, or configurable role paths — you can use [account access manager](https://docs.aws.amazon.com/IAM/latest/UserGuide/account-access-manager.html) in IAM. Account access manager lets you assign existing IAM roles to IAM Identity Center users and groups. You can use it independently or together with permission sets to gain access to the full IAM role feature set. +