Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • An IAM policy (deny-marketplace-changes-policy) that prevents making changes to the AWS Marketplace, including purchasing subscriptions
  • An IAM role (shib-limitedadmin_no_adminmarket) that combines the deny-marketplace-changes-policy policy with the built-in AdministratorAccess policy to create a role that has broad privileges in AWS, but does not allow Marketplace changes.

...

  1. In the target AWS account, create a new CloudFormation stack using the template.yaml file.
  2. Create an Active Directory group that contains the people you wish to have access to the shib-limited_admin role admin_no_market role in your AWS account.
  3. Make a request to cloud-support@cornell.edu asking that the shib-limitedadmin_no_adminmarket role be configured for use by your AWS account. Optionally, request that a similar AWS SSO role be created as well. Be sure to provide the name of the AD group you created above.
  4. Once the Cloud Team confirms that the shib-limited_admin group admin_no_market group and/or the AWS SSO role is enabled, ask your team to begin using the new role(s) when using your AWS account.

...