Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The following roles are defined in the Department Cloud Tools: 

RoleFunctionsMembers
Cloud Tools OwnersCreate a "cloud account" associated with a department OUITS Staff
OU OwnersAssign EIDs as "cloud account admins" for a cloud accountExisting owners for Active Directory departments
Cloud Account AdminsCreate and populate role groupsEIDs assigned by OU Owners to a cloud account

The process for associating a user account with an IAM role is as follows:

  1. An existing A department owner requests a new cloud account by providing for an AWS account number to ITSITS staff create a from the ITS Cloud Team via Service Now
  2. A member of the ITS Cloud Team creates a cloud account for the department with the provided AWS account number
  3. Department A department owners assign assigns EIDs as as cloud account admins for the new cloud account
  4. A cloud account admin creates role groups for AWS IAM roles
  5. A cloud account admin populates the role groups with EIDs, native Active Directory department accounts, or Active Directory groups

...