Skip to content
Discussion options

You must be logged in to vote

We currently don’t have an AWS SSO module and our team lacks expertise in the service to offer concrete steps to roll out SSO into the Reference Architecture. However, we have seen customers successfully integrate AWS SSO into the Reference Architecture in one of two ways:

Using AWS SSO as a full replacement for the security account

In this model, you configure the permission sets in SSO to directly access each of the child accounts, bypassing the security account as a concept. Most customers taking this approach either remove the security account, or keep it as a backup in case something fails in SSO and users are locked out of AWS. The drawback of this approach is that it requires manag…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@antonl
Comment options

Answer selected by pete0emerson
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment