cis13: aws identity and access management

44
AWS Identity and Access Management Jim Scharf 7/11/2013

Upload: cloudidsummit

Post on 15-Jan-2015

744 views

Category:

Travel


1 download

DESCRIPTION

Jim Scharf, Director, AWS Identity and Access Management, Amazon Amazon Web Services customers include students, startups, mobile developers, enterprises and government agencies. Learn how AWS Identity and Access Management provides access control for trillions of cloud resources.

TRANSCRIPT

Page 1: CIS13: AWS Identity and Access Management

AWS Identity and Access Management Jim Scharf 7/11/2013

Page 2: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Jim Scharf Director, AWS Identity and Access Management Joined AWS in 2004

Own •  AWS Identity and Access Management •  Authentication, Authorization •  Federation

Introductions

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  ©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Page 3: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Enable businesses and developers to use web services* to build scalable, sophisticated applications.

*What people now call “the cloud”

AWS Mission

Page 4: CIS13: AWS Identity and Access Management

Free steak campaign

Facebook page

Mars exploration operations

Consumer social app

Gene sequencing Marketing web site Interactive TV apps Financial markets analytics

Web site & media sharing

Disaster recovery Media streaming Web and mobile apps

Diverse  Customers,  Wide  Range  of  Use  Cases  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Page 5: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Mission-­‐criFcal  Projects    

Mars  Rover  Image  processing  

Video  Streaming  for  Landing  

Scale  up  as  needed  

Highly  Parallel  Processing  

Whole  World  Watching  One-­‐Time  Event  

Mars  Rovers  OperaFons

Page 6: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Panoramas  of  5  Gigapixels,  created  on  AWS  in  just  5  minutes!  

Curiosity

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Page 7: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Daily  Mars  Rover  Data  Processing  Window  (2  hours)  

Serial  Process   Upload  Plan  

Pre-­‐cloud:  

Parallel  Process   Upload  Plan  

Cloud:  

Increased  available  mission  planning  Fme  by  1.5  hours!  

Mission  Data  Processing

Page 8: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

More on NASA & AWS

AWS  Re:Invent  Conference,  2012  Keynote  Video  h\p://youtu.be/8FJ5DBLSFe4?t=11m58s    

Page 9: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

App Services Management

Compute   Networking   Storage  &    CDN  Amazon  EC2  Amazon  ElasFc  MapReduce  Amazon  ElasFc  Load  Balancer    

Amazon  Route  53  Amazon  Virtual  Private  Cloud  AWS  Direct  Connect    

Amazon  S3  Amazon  Glacier  Amazon  EBS  AWS  Import/Export  Amazon  CloudFront    

Database   App  Services   Management  Amazon  RDS  Amazon  DynamoDB  Amazon  ElasFCache  Amazon  Redshie    

Amazon  CloudSearch  Amazon  SWF  Amazon  SQS  (Queues)  Amazon  SNS  (NoFficaFons)  Amazon  SES  (Email)  Amazon  ElasFc  Transcoder    

AWS  IAM  Amazon  CloudWatch  AWS  ElasFc  Beanstalk  AWS  CloudFormaFon  AWS  Data  Pipeline  AWS  OpsWorks  AWS  CloudHSM  AWS  Trusted  Advisor  AWS  Marketplace  

AWS Services

Page 10: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Access control for AWS services and resources

AWS Identity and Access Management

Page 11: CIS13: AWS Identity and Access Management

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Page 12: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Difference #1

Page 13: CIS13: AWS Identity and Access Management

Image  courtesy  of:    h\p://im

gsrc.hub

blesite

.org/hu/db

/images/hs-­‐2005-­‐01-­‐a-­‐full_jpg.jpg  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Page 14: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

AWS Scale

•  $5.2B e-commerce company

•  7,800 employees

•  A whole lot of servers!

Every day (on average), AWS

adds server capacity equivalent

to that entire $5.2B enterprise

Page 15: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Trillions Resources

Page 16: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Million+ Requests/Second  

Page 17: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Hundreds of Thousands

Customers in 190 countries

each with one to millions of identities

Page 18: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Lots! Servers  

Page 19: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Global

Page 20: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Difference #2

Page 21: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Resources

Page 22: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Cloud Services

Amazon  EC2  

Page 23: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Instance O/S

Page 24: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Cloud Services

Amazon  EC2  

Amazon  S3  

Amazon  ElasFc  

MapReduce  

AWS  Storage  Gateway  

Amazon  DynamoDB  

Amazon  RDS  

Amazon  ElasFCache  

Amazon  Route  53  

Amazon  VPC  

Amazon  CloudFront  

Amazon  CloudWatch  

Amazon  ElasFc  

Beanstalk  

AWS  CloudFormaFon  

AWS  IAM  

Amazon  SQS  

Amazon  SES  

Amazon  SNS  

Amazon  CloudSearch  

Amazon  SWF  

Amazon Redshift

OpsWorks  

Amazon  ElasFc  Transcoder  

Page 25: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Cloud Resources

Amazon  EC2  

Amazon  S3  

Amazon  ElasFc  

MapReduce  

AWS  Storage  Gateway  

Amazon  DynamoDB  

Amazon  RDS  

Amazon  ElasFCache  

Amazon  Route  53  

Amazon  VPC  

Amazon  CloudFront  

Amazon  CloudWatch  

Amazon  ElasFc  

Beanstalk  

AWS  CloudFormaFon  

AWS  IAM  

Amazon  SQS  

Amazon  SES  

Amazon  SNS  

Amazon  CloudSearch  

Amazon  SWF  

Amazon Redshift

OpsWorks  

Amazon  ElasFc  Transcoder  

Instances   Files  

AMIs  

Spot  Instances  

Volumes  

Messages  

Snapshots  

Security  Groups  

ElasFc  IPs   Placement  Groups  Users  

Groups  Roles  

Load  Balancers  

Autoscaling  Groups  Network  Interfaces  

Queues  

Topics  

Domains  

Workflows  

ApplicaFons  

Templates  DistribuFons  

Buckets  Stacks  

Apps  

Layers   Clusters  

Page 26: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

AWS Marketplace

Page 27: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Difference #3

Page 28: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Customers •  Individual Developers •  Students

Page 29: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Hear about AWS

Page 30: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Create Account

Page 31: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Innovate!

Page 32: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Customers •  Individual Developers •  Students •  Startups •  SMBs

Page 33: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

IAM •  Users, Groups, Permissions

–  Individual security credentials –  Secure by default –  Grant least privilege

•  Easy to use –  Graphical user interface

–  Ability to script/automate (CLI & API)

Page 34: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Customers •  Individual Developers •  Students •  Startups •  SMBs •  Enterprises •  Government

Agencies

Page 35: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Control •  AWS Multi-Factor Authentication

–  Hardware tokens –  Smartphone app tokens

•  Credential management policies •  Control billing, support, and AWS Marketplace

purchases

Page 36: CIS13: AWS Identity and Access Management

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

•  HIPAA •  SOC 1/SSAE 16/ISAE

3402 (formerly SAS70) •  SOC 2 •  SOC 3 •  PCI DSS Level 1 •  ISO 27001

•  FedRAMP •  DIACAP and FISMA •  ITAR •  FIPS 140-2 •  CSA •  MPAA

Compliance

Page 37: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Federation •  AWS Websites and/or APIs as relying party •  Pre-packaged sample: Windows Active Directory as identity provider

SSO  

AcFve  Directory  

Page 38: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Federation •  Partners are critical

http://www.xceedium.com/xsuite/xsuite-for-amazon-web-services http://www.okta.com/aws/ http://www.symplified.com/solutions/single-sign-on-sso https://www.pingidentity.com/products/pingfederate/

•  More federation support coming…

Page 39: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Customers •  Individual Developers •  Students •  Startups •  SMBs •  Enterprises •  Government

Agencies •  Mobile Developers

Page 40: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Web Identity Federation

•  App sign-in using 3rd party identity providers –  –  Facebook –  Google (using OpenID Connect)

•  No server-side code required

Page 41: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Web Identity Federation

US

-EA

ST-1

AWS Services

STS  

Access  AWS  Resources  

IdenFty  Provider   Assume  Role  

Amazon  S3   Amazon  DynamoDB  

Page 42: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

Customer Evolution

Username  &  Password  

IAM  Management  UI,  CLI,  API  

MulF-­‐Factor  AuthenFcaFon  FederaFon  &  SSO    

Password  Strength  Policy  AWS  Marketplace  Control  

Enterprise  

Joe  

Startup/  SMB  

No  addiGonal  charge  

Mobile  

Page 43: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

•  Scale •  Resources •  Customers

Summary

Page 44: CIS13: AWS Identity and Access Management

©  2012  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

©  2013  Amazon.com,  Inc.  and  its  affiliates.    All  rights  reserved.    May  not  be  copied,  modified  or  distributed  in  whole  or  in  part  without  the  express  consent  of  Amazon.com,  Inc.  

[email protected] @jim_scharf Additional resources: •  AWS Security Blog: http://blogs.aws.amazon.com/security/ •  AWS IAM: http://aws.amazon.com/iam/ •  AWS IAM on Twitter: @AWSIdentity

Thank You!

RegistraGon  opens  July  17,  9  AM  PDT  Last  year,  it  sold  out,  so  register  early