The cloud identity management feature hosts AWS accounts and their IAM roles in IDaaS for centralized identity governance and access control. You can use this feature to manage scattered AWS accounts and simplify permission management across multiple accounts.
Prerequisites
Machine identity management must be enabled for the target instance.
You must have an AWS account to be hosted and be able to access the IAM console of that account.
Add a cloud account
Adding a cloud account involves two steps: first, enter the AWS account information in IDaaS, and then complete the system role configuration in the AWS IAM console.
Log on to the IDaaS admin console. Select the target instance and click Access Console in the Actions column.
Add cloud account information.
a. In the left-side navigation pane, choose Asset Management > Asset Management > Cloud Identity.
b. Click Add Cloud Account.
c. For Cloud Provider, select AWS and enter the following information:
Parameter
Description
Site
Select China Site or International based on the site of your AWS account.
Account ID
The primary account ID of the AWS account that you want to add. The account ID must be exactly 12 digits.
d. Click Next.
Configure unified identity.
NoteThe system role is used to automatically discover and synchronize cloud roles, retrieve hosted container asset information, and verify identity provider compliance.
Follow the on-screen instructions to complete the following configurations in the IAM console of the target AWS account:
Configure an identity provider.
The following parameters are displayed on the page. Enter them into the corresponding configuration items in the AWS IAM console to create an OIDC identity provider:
Parameter
Description
Provider URL
The identity provider URL issued by IDaaS. Click to copy.
Audience
The audience identifier. Click to copy.
For detailed steps, see Creating an OpenID Connect (OIDC) identity provider in IAM in the AWS documentation.
Create a role.
Create a role in the AWS IAM console:
Go to the role creation page in the IAM console.
Select the trusted entity type.
Enter the role name as
idaas-eiam-system-role. You can copy the name from the page.
NoteThe role name is fixed as
idaas-eiam-system-roleand cannot be changed.For detailed steps, see Creating a role for OpenID Connect federation (console) in the AWS documentation.
Create an inline policy.
Go to the role that you created, click the Permissions tab, choose Add permissions > Create inline policy, select JSON in the policy editor, and then copy the inline policy script displayed on the IDaaS page and paste it into the editor.
If the policy content is not loaded, click Reload to retrieve the policy document again.
Click Start Detection. IDaaS detects whether the system role is configured correctly.
Detection passed: A success message is displayed. Click Close to complete the cloud account addition.
Detection failed: The error cause is displayed. Correct the configuration based on the prompts and click Re-check.
If the configuration is incomplete but you have exited the page, go to Asset Management > Asset Management > Cloud Identity, find the cloud account that you added, and click Cloud Role Management in the Actions column. Then click Details and click Configure System Role to continue the configuration by following the on-screen instructions.
After the configuration is complete, you can view the added cloud account on the Asset Management > Asset Management > Cloud Identity page. Click Cloud Role Management in the Actions column of the target cloud account to view the system role.
Add cloud roles
Host cloud roles under the target cloud account in IDaaS.
On the Asset Management > Asset Management page, select a hosted cloud account. If the account is not hosted, complete the add a cloud account procedure first. Click Cloud Role Management in the Actions column.
Click Add Cloud Role.
a. Role Name: Select the IAM role that you want to host in IDaaS.
b. Trust Policy: Follow the on-screen instructions to complete the configuration in the IAM console of the cloud account. For detailed steps, see Creating a role for OpenID Connect federation (console) or updating the role trust policy.
Click Confirm to complete the cloud role addition.
After the configuration is complete, you can view the cloud account on the Asset Management > Asset Management page. Click Cloud Role Management in the Actions column of the target cloud account to view the added cloud roles.
Principle of least privilege: Configure precise access policies for the hosted IAM roles. Grant only the minimum permissions required for business operations. Avoid using overly broad authorizations such as *:*.
Delete cloud roles
On the Asset Management > Asset Management > Cloud Identity page, select a hosted cloud account and click Cloud Role Management in the Actions column.
In the cloud role list, find the target cloud role and click the toggle switch in the Cloud Role Status column to disable the cloud role.
ImportantDisabling a cloud role prevents applications and users from using the corresponding role. Verify the business impact before you proceed.
In the cloud role list, find the target cloud role and click Delete in the Actions column.
Delete a cloud account
Before you delete a cloud account, you must delete all user-created cloud roles under the account.
On the Asset Management > Asset Management > Cloud Identity page, find the target cloud account and click Delete in the Actions column.